Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
1343 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (3.7) | 0.34% | — | Nodejs Node.js | 22/6/2026 | 3/7/2026 | A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| Analizada | Media (5.3) | 0.41% | — | Nodeca Js-yaml | 22/6/2026 | 9/7/2026 | js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a… | |
| Analizada | Alta (7.5) | 0.57% | — | Nodejs Node.js | 18/6/2026 | 18/8/2026 | A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**. | |
| Analizada | Alta (8.2) | 0.32% | — | Nodejs Node.js | 18/6/2026 | 19/8/2026 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**,… | |
| Modificada | Alta (7.4) | 0.55% | — | Nodejs Undici | 17/6/2026 | 10/9/2026 | Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings.… | |
| Analizada | Media (5.9) | 0.33% | — | Nodejs Undici | 17/6/2026 | 25/6/2026 | Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 §5.4 does not specify any decoding and browsers do not decode either. Applications that parse a Set-Cookie header and… | |
| Analizada | Media (5.9) | 0.42% | — | Nodejs Undici | 17/6/2026 | 25/6/2026 | Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=" authorization" or no-cache="\tauthorization". The parser preserves the surrounding whitespace, so later… | |
| Modificada | Alta (8.8) | 0.39% | — | Nodejs Undici | 17/6/2026 | 10/9/2026 | Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended destination. This causes cross-origin… | |
| Analizada | Baja (3.7) | 0.27% | — | Nodejs Undici | 17/6/2026 | 27/6/2026 | Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the… | |
| Analizada | Baja (3.7) | 0.24% | — | Nodejs Undici | 17/6/2026 | 25/6/2026 | Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example,… | |
| Analizada | Alta (7.5) | 0.49% | — | Nodejs Undici | 17/6/2026 | 25/6/2026 | Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket server can stream many small fragments that each pass per-frame validation but collectively exceed the configured limit, causing unbounded memory… | |
| Modificada | Alta (7.5) | 0.79% | — | Nodejs Undici | 17/6/2026 | 11/9/2026 | Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation,… | |
| Aplazada | Baja (3.7) | 0.32% | — | ApostrophecmsAINodejsAI | 12/6/2026 | 17/6/2026 | ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyUrls: true` is enabled on `@apostrophecms/file` (a documented SEO feature for serving uploaded files at clean URLs), the public pretty-URL handler builds the upstream URL using the raw `Host` HTTP… | |
| Analizada | Alta (7.5) | 5.0% | — | Openjsf Node Version Manager | 4/6/2026 | 22/7/2026 | nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured Node.js/io.js mirror. Commands such as `nvm install` read the available versions from the mirror's index.tab and use the selected version, without sanitization, to build download URLs and shell/awk… | |
| Aplazada | Alta (8.7) | 0.37% | — | Haxtheweb Haxcms NodejsAIHaxcms PHPAI | 29/5/2026 | 21/7/2026 | HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) vulnerability in the `/system/api/saveNode` endpoint. An authenticated user with a permission to edit pages can bypass the HTML sanitizer by injecting an event… | |
| Analizada | Alta (7.5) | 0.49% | — | Opentelemetry/auto-instrumentations-nodeOpentelemetry/exporter-prometheusOpentelemetry/sdk-node | 27/5/2026 | 27/8/2026 | opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics endpoint (default 0.0.0.0:9464) has no error handling around URL parsing, so a request with an invalid URI causes an… | |
| Aplazada | Media (4.4) | 0.10% | — | Nuts-nodeAI | 26/5/2026 | 24/7/2026 | nuts-node is the reference implementation of the Nuts specification. Prior to 6.2.3 and 5.4.31, the v1 access token introspection endpoint (/auth/v1/introspect_access_token) accepts any JWT signed by a key present on the node, without validating the JWT type, issuer-to-key binding, or required claims. This allows a… | |
| Analizada | Baja (3.7) | 0.27% | — | Adcisolutions Node View Permissions | 19/5/2026 | 23/7/2026 | Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing. This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.1. | |
| Aplazada | Alta (7.5) | 0.75% | — | Nodemailer Smtp ServerAI | 15/5/2026 | 17/6/2026 | An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components | |
| Aplazada | Alta (8.6) | 0.47% | — | 18next Http-middlewareAINodejsAIExpressAIFastifyAI+1 | 8/5/2026 | 17/6/2026 | 18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. Versions prior to 3.9.3 allow an unauthenticated HTTP client to pollute Object.prototype in the Node.js process hosting the middleware, via two unvalidated entry points that reach internal… | |
| Pendiente de análisis | Alta (8.8) | 1.2% | — | NPM Node-ts-ocrAI | 7/5/2026 | 17/6/2026 | NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js. | |
| Aplazada | Alta (8.3) | 0.37% | — | TwentyAINodejsAINestjsAI | 5/5/2026 | 24/7/2026 | Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientService can be bypassed using IPv4-mapped IPv6 addresses in URL IP literals. Node.js's URL parser normalizes IPv4-mapped IPv6 addresses to compressed hex form (e.g.,… | |
| Aplazada | Media (5.3) | 0.40% | — | Ovirt NodeAI | 24/4/2026 | 17/6/2026 | @astrojs/node allows Astro to deploy your SSR site to Node targets. Prior to 10.0.5, requesting a static js/css resources from _astro path with an incorrect/malformed if-match header returns a 500 error with a one year cache lifetime instead of 412 in some cases. This has the effect that all subsequent requests to… | |
| Analizada | Media (5.9) | 0.35% | — | Node-oauth/oauth2-server | 23/4/2026 | 17/6/2026 | @node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character strings) for S256 PKCE flows. Because short/weak verifiers are accepted and failed verifier attempts do not consume the authorization code,… | |
| Analizada | Alta (7.8) | 0.22% | — | Node-modules Compressing | 21/4/2026 | 17/6/2026 | Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical string validation within the isPathWithinParent utility. This check verifies if a resolved path string starts with the destination directory string but fails to account for… |