Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 303 respecto a la semana anterior
Críticas / altas1351▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.9) | 0.33% | — | Nodejs Undici | 17/6/2026 | 25/6/2026 | Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 §5.4 does not specify any decoding and browsers do not decode either. Applications that parse a Set-Cookie header and… | |
| Analizada | Media (5.9) | 0.42% | — | Nodejs Undici | 17/6/2026 | 25/6/2026 | Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=" authorization" or no-cache="\tauthorization". The parser preserves the surrounding whitespace, so later… | |
| Modificada | Alta (8.8) | 0.39% | — | Nodejs Undici | 17/6/2026 | 10/9/2026 | Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended destination. This causes cross-origin… | |
| Analizada | Baja (3.7) | 0.27% | — | Nodejs Undici | 17/6/2026 | 27/6/2026 | Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the… | |
| Analizada | Baja (3.7) | 0.24% | — | Nodejs Undici | 17/6/2026 | 25/6/2026 | Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example,… | |
| Analizada | Alta (7.5) | 0.49% | — | Nodejs Undici | 17/6/2026 | 25/6/2026 | Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket server can stream many small fragments that each pass per-frame validation but collectively exceed the configured limit, causing unbounded memory… | |
| Modificada | Alta (7.5) | 0.79% | — | Nodejs Undici | 17/6/2026 | 11/9/2026 | Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation,… | |
| Aplazada | Baja (3.7) | 0.32% | — | ApostrophecmsAINodejsAI | 12/6/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyUrls: true` is enabled on `@apostrophecms/file` (a documented SEO feature for serving uploaded files at clean URLs), the public pretty-URL handler builds the upstream URL using the raw `Host` HTTP… | |
| Aplazada | Alta (8.7) | 0.37% | — | Haxtheweb Haxcms NodejsAIHaxcms PHPAI | 29/5/2026 | 21/7/2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) vulnerability in the `/system/api/saveNode` endpoint. An authenticated user with a permission to edit pages can bypass the HTML sanitizer by injecting an event… | |
| Aplazada | Alta (8.6) | 0.47% | — | 18next Http-middlewareAINodejsAIExpressAIFastifyAI+1 | 8/5/2026 | 17/6/2026 | 18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allow an unauthenticated HTTP client to pollute Object.prototype in the Node.js process hosting the middleware, via two unvalidated entry points that reach internal… | |
| Aplazada | Alta (8.3) | 0.37% | — | TwentyAINodejsAINestjsAI | 5/5/2026 | 24/7/2026 | Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientService can be bypassed using IPv4-mapped IPv6 addresses in URL IP literals. Node.js's URL parser normalizes IPv4-mapped IPv6 addresses to compressed hex form (e.g.,… | |
| Analizada | Media (5.9) | 0.27% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process. The most… | |
| Analizada | Baja (3.3) | 0.15% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly patched. As a result, code running under `--permission` with restricted… | |
| Analizada | Baja (3.3) | 0.16% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use… | |
| Analizada | Media (5.3) | 0.45% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2… | |
| Analizada | Media (5.9) | 0.39% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as… | |
| Analizada | Media (5.3) | 0.18% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can create and expose local IPC endpoints,… | |
| Analizada | Alta (7.5) | 25% | — | Nodejs Node.jsRedhat Enterprise LinuxRedhat Enterprise Linux EUS | 30/3/2026 | 19/8/2026 | A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a… | |
| Analizada | Media (6.5) | 0.32% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process. | |
| Pendiente de análisis | Alta (7.1) | 0.45% | — | Elixir-nodejsAI | 27/3/2026 | 17/6/2026 | elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results in Cross-User Data Leakage or Information Disclosure due to a race condition in the worker protocol. The lack of request-response correlation creates a "stale response" vulnerability. Because the… | |
| Analizada | Media (5.9) | 0.71% | — | Nodejs Undici | 12/3/2026 | 17/6/2026 | This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests could be accumulated in memory for downstream handlers. An attacker-controlled or untrusted… | |
| Modificada | Alta (7.5) | 0.87% | — | Nodejs Undici | 12/3/2026 | 4/9/2026 | ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automatically advertises support for permessage-deflate compression. A malicious server… | |
| Modificada | Alta (7.5) | 0.49% | — | Nodejs Undici | 12/3/2026 | 4/9/2026 | ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade… | |
| Analizada | Media (4.6) | 0.28% | — | Nodejs Undici | 12/3/2026 | 17/6/2026 | ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\r\n) to: | |
| Modificada | Alta (7.5) | 1.1% | — | Nodejs Undici | 12/3/2026 | 4/9/2026 | The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed… |