Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2533▼ 411 respecto a la semana anterior
Críticas / altas1305▲ 22 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
215 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.40% | — | Nodejs Node.js | 26/6/2026 | 26/6/2026 | A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported… | |
| Modificada | Baja (3.7) | 0.34% | — | Nodejs Node.js | 22/6/2026 | 3/7/2026 | A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Analizada | Alta (7.5) | 0.57% | — | Nodejs Node.js | 18/6/2026 | 18/8/2026 | A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**. | |
| Analizada | Alta (8.2) | 0.32% | — | Nodejs Node.js | 18/6/2026 | 19/8/2026 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**,… | |
| Analizada | Media (5.9) | 0.27% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process. The most… | |
| Analizada | Baja (3.3) | 0.15% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly patched. As a result, code running under `--permission` with restricted… | |
| Analizada | Baja (3.3) | 0.16% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use… | |
| Analizada | Media (5.3) | 0.45% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2… | |
| Analizada | Media (5.9) | 0.39% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as… | |
| Analizada | Media (5.3) | 0.18% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can create and expose local IPC endpoints,… | |
| Analizada | Alta (7.5) | 25% | — | Nodejs Node.jsRedhat Enterprise LinuxRedhat Enterprise Linux EUS | 30/3/2026 | 19/8/2026 | A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a… | |
| Analizada | Media (6.5) | 0.32% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process. | |
| Analizada | Alta (7.5) | 1.1% | — | Nodejs Node.js | 20/1/2026 | 17/6/2026 | A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process… | |
| Analizada | Crítica (10) | 0.88% | — | Nodejs Node.js | 20/1/2026 | 17/6/2026 | A flaw in Node.js's permission model allows Unix Domain Socket (UDS) connections to bypass network restrictions when `--permission` is enabled. Even without `--allow-net`, attacker-controlled inputs (such as URLs or socketPath options) can connect to arbitrary local sockets via net, tls, or undici/fetch. This breaks… | |
| Analizada | Alta (7.5) | 0.69% | — | Nodejs Node.js | 20/1/2026 | 17/6/2026 | We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on('uncaughtException')`, the process terminates, making the crash unrecoverable. Applications that rely on `AsyncLocalStorage`… | |
| Modificada | Alta (7.5) | 4.0% | — | Nodejs Node.js | 20/1/2026 | 15/7/2026 | — | |
| Analizada | Alta (7.5) | 0.27% | — | Nodejs Node.js | 20/1/2026 | 17/6/2026 | A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When applications call `socket.getPeerCertificate(true)`, each certificate field leaks memory, allowing remote clients to trigger steady memory growth through repeated TLS… | |
| Analizada | Media (5.3) | 0.26% | — | Nodejs Node.js | 20/1/2026 | 17/6/2026 | A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories.… | |
| Aplazada | Alta (7.1) | 3.5% | — | Nodejs Node.jsAI | 20/1/2026 | 15/7/2026 | A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and other `TypedArray` instances like `Uint8Array` may contain leftover data from… | |
| Modificada | Crítica (9.1) | 1.7% | — | Nodejs Node.js | 20/1/2026 | 15/7/2026 | A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the… | |
| Aplazada | Alta (7.5) | 15% | — | Nodejs Node.jsAI | 18/7/2025 | 17/6/2026 | An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API. | |
| Aplazada | Baja (3.7) | 0.55% | — | Nodejs Node.jsAI | 19/5/2025 | 17/6/2026 | In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable memory leak on every call. Repeated use can cause unbounded memory growth, leading… | |
| Aplazada | Media (5.3) | 1.4% | — | Nodejs Node.jsAI | 7/2/2025 | 17/6/2026 | A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential… | |
| Modificada | Media (5.5) | 1.6% | — | Nodejs Node.js | 28/1/2025 | 17/6/2026 | A vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.js functions do not treat drive names as special on Windows. As a result, although Node.js assumes a relative path, it actually refers to the root directory. On Windows, a path… | |
| Aplazada | Alta (8.1) | 1.4% | — | Nodejs Node.jsAI | 9/1/2025 | 17/6/2026 | Due to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject arbitrary commands and achieve code execution even if the shell option is not enabled. |