Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1338▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
1343 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.27% | — | Geosolutionsgroup Geonode | 10/4/2026 | 14/7/2026 | GeoNode versions 4.4.5 and 5.0.2 (and prior within their respective releases) contain a server-side request forgery vulnerability in the service registration endpoint that allows authenticated attackers to trigger outbound network requests to arbitrary URLs by submitting a crafted service URL during form validation.… | |
| Modificada | Media (5.3) | 0.37% | — | Geosolutionsgroup Geonode | 10/4/2026 | 14/7/2026 | GeoNode versions 4.0 before 4.4.5 and 5.0 before 5.0.2 contain a server-side request forgery vulnerability that allows authenticated users with document upload permissions to trigger arbitrary outbound HTTP requests by providing a malicious URL via the doc_url parameter during document upload. Attackers can supply… | |
| Analizada | Media (5.3) | 0.40% | — | Hono Node-server | 8/4/2026 | 24/7/2026 | @hono/node-server allows running the Hono application on Node.js. Prior to 1.19.13, a path handling inconsistency in serveStatic allows protected static files to be accessed by using repeated slashes (//) in the request path. When route-based middleware (e.g., /admin/*) is used for authorization, the router may not… | |
| Pendiente de análisis | Media (4.6) | 0.24% | — | Aziot Node Smart Switch 16ampAI | 6/4/2026 | 5/7/2026 | An information disclosure vulnerability exists in AZIOT 1 Node Smart Switch (16amp)- WiFi/Bluetooth Enabled Software Version: 1.1.9 due to improper access control on the UART debug interface. An attacker with physical access can connect to the UART interface and obtain sensitive information from the serial console… | |
| Analizada | Media (5.9) | 0.27% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process. The most… | |
| Analizada | Baja (3.3) | 0.15% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly patched. As a result, code running under `--permission` with restricted… | |
| Analizada | Baja (3.3) | 0.16% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use… | |
| Analizada | Media (5.3) | 0.45% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2… | |
| Analizada | Media (5.9) | 0.39% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as… | |
| Analizada | Media (5.3) | 0.18% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can create and expose local IPC endpoints,… | |
| Analizada | Alta (7.5) | 25% | — | Nodejs Node.jsRedhat Enterprise LinuxRedhat Enterprise Linux EUS | 30/3/2026 | 19/8/2026 | A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, causing `.push()` to be called on a… | |
| Analizada | Media (6.5) | 0.32% | — | Nodejs Node.js | 30/3/2026 | 19/8/2026 | A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process. | |
| Pendiente de análisis | Alta (7.1) | 0.45% | — | Elixir-nodejsAI | 27/3/2026 | 17/6/2026 | elixir-nodejs provides an Elixir API for calling Node.js functions. A vulnerability in versions prior to 3.1.4 results in Cross-User Data Leakage or Information Disclosure due to a race condition in the worker protocol. The lack of request-response correlation creates a "stale response" vulnerability. Because the… | |
| Analizada | Alta (7.5) | 0.39% | — | Jeroenb Unpublished Node Permissions | 26/3/2026 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal Unpublished Node Permissions allows Forceful Browsing.This issue affects Unpublished Node Permissions: from 0.0.0 before 1.7.0. | |
| Analizada | Alta (7.5) | 0.43% | — | @astrojs/node | 24/3/2026 | 17/6/2026 | Astro is a web framework. Prior to version 10.0.0, Astro's Server Islands POST handler buffers and parses the full request body as JSON without enforcing a size limit. Because JSON.parse() allocates a V8 heap object for every element in the input, a crafted payload of many small JSON objects achieves ~15x memory… | |
| Aplazada | Media (5.5) | 0.47% | — | Jawherkl Node-api-postgresAI | 16/3/2026 | 17/6/2026 | A flaw has been found in JawherKl node-api-postgres up to 2.5. Affected is the function path.extname of the file index.js of the component Profile Picture Handler. This manipulation causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been published and may be used. The vendor… | |
| Aplazada | Media (5.5) | 0.41% | — | Jawherkal Node-api-postgresAI | 16/3/2026 | 17/6/2026 | A vulnerability was detected in JawherKl node-api-postgres up to 2.5. This impacts the function User.getAll of the file models/user.js. The manipulation of the argument sort results in sql injection. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about… | |
| Analizada | Media (5.9) | 0.71% | — | Nodejs Undici | 12/3/2026 | 17/6/2026 | This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests could be accumulated in memory for downstream handlers. An attacker-controlled or untrusted… | |
| Modificada | Alta (7.5) | 0.87% | — | Nodejs Undici | 12/3/2026 | 4/9/2026 | ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automatically advertises support for permessage-deflate compression. A malicious server… | |
| Modificada | Alta (7.5) | 0.49% | — | Nodejs Undici | 12/3/2026 | 4/9/2026 | ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version v7.24.0 and v6.24.0. Users should upgrade… | |
| Analizada | Media (4.6) | 0.28% | — | Nodejs Undici | 12/3/2026 | 17/6/2026 | ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\r\n) to: | |
| Modificada | Alta (7.5) | 1.1% | — | Nodejs Undici | 12/3/2026 | 4/9/2026 | The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without enforcing any limit on the decompressed… | |
| Analizada | Crítica (9.8) | 0.49% | — | Nodejs Undici | 12/3/2026 | 17/6/2026 | Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the wire. Who is impacted: Potential consequences: | |
| Modificada | Crítica (9.8) | 0.95% | — | Linuxfoundation Backstage Plugin-techdocs-node | 7/3/2026 | 15/7/2026 | Backstage is an open framework for building developer portals. Prior to version 1.14.3, this is a configuration bypass vulnerability that enables arbitrary code execution. The @backstage/plugin-techdocs-node package uses an allowlist to filter dangerous MkDocs configuration keys during the documentation build process.… | |
| Analizada | Alta (7.5) | 0.43% | — | Hono Node-server | 6/3/2026 | 17/6/2026 | @hono/node-server allows running the Hono application on Node.js. Prior to version 1.19.10, when using @hono/node-server's static file serving together with route-based middleware protections (e.g. protecting /admin/*), inconsistent URL decoding can allow protected static resources to be accessed without… |