Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2570▼ 302 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.7) | 0.16% | — | Google RE2AINodejs Node.jsAI | 30/7/2026 | 10/9/2026 | re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a subject but uses it as a UTF-16 code-unit offset in exec, test, match, replace, and split, allowing an attacker-influenced lastIndex on a non-ASCII subject to trigger an… | |
| Analizada | Alta (8.4) | 0.15% | — | Nodejs Node.js | 30/7/2026 | 25/8/2026 | A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects… | |
| Pendiente de análisis | Media (6.3) | 0.28% | — | Nodejs Node.jsAI | 30/7/2026 | 3/9/2026 | An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**. | |
| Analizada | Media (4.4) | 0.08% | — | Nodejs Node.js | 30/7/2026 | 25/8/2026 | A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**. | |
| Analizada | Media (6.1) | 0.16% | — | Nodejs Node.js | 30/7/2026 | 25/8/2026 | A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and… | |
| Analizada | Media (5.4) | 0.19% | — | Nodejs Undici | 29/7/2026 | 4/8/2026 | undici does not validate the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, an application that passes a hand-rolled blob-like body (via request,… | |
| Analizada | Alta (7.5) | 0.40% | — | Nodejs Undici | 29/7/2026 | 4/8/2026 | undici's cache interceptor mishandles optional whitespace placed around the equals sign of a qualified no-cache or private Cache-Control directive. In undici from 7.0.0 up to before 7.29.0 and from 8.0.0 up to before 8.9.0, the parser either drops the directive or stores a field name with literal quote characters, so… | |
| Analizada | Media (6.5) | 0.18% | — | Nodejs Undici | 29/7/2026 | 4/8/2026 | undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to the application after a retry or resume of a partial response. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a malicious or faulty upstream can return a… | |
| Analizada | Media (6.5) | 0.19% | — | Nodejs Undici | 29/7/2026 | 5/8/2026 | undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to before 8.9.0, a domain value is not checked for semicolons and entries in the unparsed array are not sanitized, so attacker-influenced input can inject additional cookie… | |
| Analizada | Crítica (9.1) | 0.57% | — | Nodejs Undici | 29/7/2026 | 4/8/2026 | undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a response carrying a degenerate qualified private directive, such as private set to an empty value, can be stored in the default shared cache and later served to a… | |
| Pendiente de análisis | Baja (2.1) | 0.34% | — | NodejsAIOpenjsf Node Version ManagerAI | 15/7/2026 | 16/7/2026 | Node Version Manager (nvm) is a POSIX-compliant shell function for managing multiple node.js versions. In versions 0.32.1 through 0.40.5, `nvm ls-remote` (and other commands that refresh remote LTS aliases, such as `nvm install --lts`) parse the node.js mirror's `index.tab` and use each release's LTS codename field as… | |
| Analizada | Baja (3.3) | 0.14% | — | Nodejs Node.js | 26/6/2026 | 26/6/2026 | A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**. | |
| Analizada | Baja (3.3) | 0.18% | — | Nodejs Node.js | 26/6/2026 | 26/6/2026 | A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Modificada | Media (4.3) | 0.26% | — | Nodejs Node.js | 26/6/2026 | 29/6/2026 | A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Modificada | Alta (7.5) | 3.7% | — | Nodejs Node.js | 26/6/2026 | 10/8/2026 | A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Analizada | Crítica (9.8) | 0.32% | — | Nodejs Node.js | 26/6/2026 | 26/6/2026 | A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Analizada | Media (5.4) | 0.22% | — | Nodejs Node.js | 26/6/2026 | 26/6/2026 | A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Analizada | Alta (7.5) | 0.64% | — | Nodejs Node.js | 26/6/2026 | 26/6/2026 | A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Modificada | Media (6.5) | 3.2% | — | Nodejs Node.js | 26/6/2026 | 10/8/2026 | A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.… | |
| Analizada | Alta (7.5) | 0.40% | — | Nodejs Node.js | 26/6/2026 | 26/6/2026 | A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all supported… | |
| Aplazada | Media (5.3) | 0.36% | — | GhostAINodejsAISqliteAIMysqlAI | 24/6/2026 | 25/6/2026 | Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partially bypassed, making it possible to reveal private fields via a brute force attack. If SQLite was used as the database password hashes were fully accessible. If MySQL was… | |
| Modificada | Baja (3.7) | 0.34% | — | Nodejs Node.js | 22/6/2026 | 3/7/2026 | A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Analizada | Alta (7.5) | 0.57% | — | Nodejs Node.js | 18/6/2026 | 18/8/2026 | A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**. | |
| Analizada | Alta (8.2) | 0.32% | — | Nodejs Node.js | 18/6/2026 | 19/8/2026 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**,… | |
| Modificada | Alta (7.4) | 0.55% | — | Nodejs Undici | 17/6/2026 | 10/9/2026 | Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings.… |