Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2612▼ 295 respecto a la semana anterior
Críticas / altas1346▲ 82 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

215 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.5%—Nodejs Node.jsFedoraproject Fedora15/8/202317/6/2026
The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x, and, 20.x. Please note that at the time…
ModificadaAlta (8.8)2.1%—Nodejs Node.jsFedoraproject Fedora15/8/202317/6/2026
A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of Buffers in file system APIs causing a traversal path to bypass when verifying file permissions. This vulnerability affects all users using the experimental…
ModificadaMedia (5.3)1.2%—Nodejs Node.jsFedoraproject Fedora15/8/202317/6/2026
`fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. This flaw arises from a missing check in the fs.mkdtemp() API and the impact is a malicious actor could create an arbitrary directory. This vulnerability affects all users using the experimental…
ModificadaAlta (7.5)3.9%—Nodejs Node.jsFedoraproject Fedora1/7/202317/6/2026
The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence…
ModificadaAlta (7.5)1.3%—Nodejs Node.js1/7/202317/6/2026
A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental permission model is enabled, which can bypass and/or disable the permission model. The attack complexity is high. However, the crypto.setEngine() API can be used to bypass the permission model…
ModificadaMedia (6.1)0.40%—Redhat Keycloak Node.js AdapterRedhat Single Sign-on27/3/202317/6/2026
A flaw was found in the Keycloak Node.js Adapter. This flaw allows an attacker to benefit from an Open Redirect vulnerability in the checkSso function.
ModificadaMedia (4.2)0.47%—Nodejs Node.jsDebian Linux23/2/202317/6/2026
An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges.
ModificadaAlta (7.5)2.2%—Nodejs Node.js23/2/202317/6/2026
A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the OpenSSL error stack after operations that may set it. This may lead to false positive errors during subsequent cryptographic operations that happen to be on the same thread. This in turn…
ModificadaAlta (7.5)2.0%—Nodejs Node.js23/2/202317/6/2026
A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who…
ModificadaMedia (5.4)1.1%—Nodejs Node.jsNodejs Undici16/2/202317/6/2026
Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` string before passing to undici.
ModificadaAlta (8.1)15%—Nodejs Node.jsDebian Linux5/12/202217/6/2026
A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this…
ModificadaMedia (6.5)2.8%—Nodejs Node.jsLlhttpSiemens Sinec INSDebian Linux5/12/202217/6/2026
The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling.
ModificadaCrítica (9.1)2.1%—Nodejs Node.jsSiemens Sinec INSDebian Linux5/12/202217/6/2026
A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes…
ModificadaAlta (7.5)92%—OpensslFedoraproject FedoraNodejs Node.js1/11/202217/6/2026
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for an application to continue certificate verification despite failure…
ModificadaAlta (7.5)91%—OpensslFedoraproject FedoraNetapp Clustered Data OntapNodejs Node.js1/11/202217/6/2026
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite…
ModificadaAlta (7.3)1.8%—Nodejs Node.js14/7/202217/6/2026
Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploited if the victim has the following dependencies on a Windows machine:* OpenSSL has been installed and “C:\Program Files\Common Files\SSL\openssl.cnf” exists.Whenever the above…
ModificadaMedia (5.3)2.2%—Nodejs Node.jsSiemens Sinec INS14/7/202217/6/2026
A cryptographic vulnerability exists on Node.js on linux in versions of 18.x prior to 18.40.0 which allowed a default path for openssl.cnf that might be accessible under some circumstances to a non-admin user instead of /etc/ssl as was the case in versions prior to the upgrade to OpenSSL 3.
ModificadaMedia (6.5)70%—LlhttpNodejs Node.jsFedoraproject FedoraSiemens Sinec INS+214/7/202217/6/2026
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly handle multi-line Transfer-Encoding headers. This can lead to HTTP Request Smuggling (HRS).
ModificadaMedia (6.5)82%—LlhttpNodejs Node.jsDebian LinuxStormshield Management Center14/7/202217/6/2026
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).
ModificadaMedia (6.5)46%—LlhttpNodejs Node.jsFedoraproject FedoraSiemens Sinec INS+214/7/202217/6/2026
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).
ModificadaAlta (8.1)6.4%—Nodejs Node.jsDebian LinuxFedoraproject FedoraSiemens Sinec INS14/7/202217/6/2026
A OS Command Injection vulnerability exists in Node.js versions <14.20.0, <16.20.0, <18.5.0 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.
ModificadaAlta (7.5)73%—OpensslDebian LinuxNetapp Cloud Volumes Ontap MediatorNetapp Clustered Data Ontap+915/3/202217/6/2026
The BN_mod_sqrt() function, which computes a modular square root, contains a bug that can cause it to loop forever for non-prime moduli. Internally this function is used when parsing certificates that contain elliptic curve public keys in compressed form or explicit elliptic curve parameters with a base point encoded…
ModificadaAlta (8.2)22%—Nodejs Node.jsOracle Mysql ClusterOracle Mysql ConnectorsOracle Mysql Enterprise Monitor+724/2/202217/6/2026
Due to the formatting logic of the "console.table()" function it was not safe to allow user controlled input to be passed to the "properties" parameter while simultaneously passing a plain object with at least one property as the first parameter, which could be "__proto__". The prototype pollution has very limited…
ModificadaMedia (5.3)9.4%—Nodejs Node.jsOracle GraalvmOracle Mysql ClusterOracle Mysql Connectors+524/2/202217/6/2026
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 did not handle multi-value Relative Distinguished Names correctly. Attackers could craft certificate subjects containing a single-value Relative Distinguished Name that would be interpreted as a multi-value Relative Distinguished Name, for example, in order to…
ModificadaMedia (5.3)10%—Nodejs Node.jsOracle GraalvmOracle Mysql ClusterOracle Mysql Connectors+524/2/202217/6/2026
Node.js < 12.22.9, < 14.18.3, < 16.13.2, and < 17.3.1 converts SANs (Subject Alternative Names) to a string format. It uses this string to check peer certificates against hostnames when validating connections. The string format was subject to an injection vulnerability when name constraints were used within a…