Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 363 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
305 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | Nodejs Node.js | 12/9/2023 | 17/6/2026 | The use of the deprecated API `process.binding()` can bypass the permission model through path traversal. This vulnerability affects all users using the experimental permission model in Node.js 20.x. Please note that at the time this CVE was issued, the permission model is an experimental feature of Node.js. | |
| Modificada | Media (5.3) | 1.4% | — | Nodejs Node.js | 12/9/2023 | 17/6/2026 | A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an inadequate permission model that fails to restrict file stats through the `fs.statfs` API. As a result, malicious actors… | |
| Modificada | Alta (7.5) | 1.8% | — | Nodejs Node.js | 24/8/2023 | 17/6/2026 | A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the deprecated API `process.binding()` can bypass the policy mechanism by requiring internal modules and eventually take advantage of `process.binding('spawn_sync')` run… | |
| Modificada | Crítica (9.8) | 1.6% | — | Nodejs Node.js | 21/8/2023 | 17/6/2026 | The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. Please note that at the time this CVE was issued, the… | |
| Modificada | Alta (7.5) | 0.63% | — | Jenkins Nodejs | 16/8/2023 | 17/6/2026 | Jenkins NodeJS Plugin 1.6.0 and earlier does not properly mask (i.e., replace with asterisks) credentials specified in the Npm config file in Pipeline build logs. | |
| Modificada | Alta (8.8) | 1.5% | — | Nodejs Node.jsFedoraproject Fedora | 15/8/2023 | 17/6/2026 | The use of `module.constructor.createRequire()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. This vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x, and, 20.x. Please note that at the time… | |
| Modificada | Alta (8.8) | 2.1% | — | Nodejs Node.jsFedoraproject Fedora | 15/8/2023 | 17/6/2026 | A vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improper handling of Buffers in file system APIs causing a traversal path to bypass when verifying file permissions. This vulnerability affects all users using the experimental… | |
| Modificada | Media (5.3) | 1.2% | — | Nodejs Node.jsFedoraproject Fedora | 15/8/2023 | 17/6/2026 | `fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. This flaw arises from a missing check in the fs.mkdtemp() API and the impact is a malicious actor could create an arbitrary directory. This vulnerability affects all users using the experimental… | |
| Modificada | Crítica (9.8) | 1.9% | — | Syncfusion Nodejs File System Provider | 12/7/2023 | 17/6/2026 | The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can: - On Windows, list files in any directory, read any file, delete any file, upload any file to any directory accessible by the web server. - On Linux, read any file,… | |
| Modificada | Alta (7.5) | 3.9% | — | Nodejs Node.jsFedoraproject Fedora | 1/7/2023 | 17/6/2026 | The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS). The CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence… | |
| Modificada | Alta (7.5) | 1.3% | — | Nodejs Node.js | 1/7/2023 | 17/6/2026 | A privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental permission model is enabled, which can bypass and/or disable the permission model. The attack complexity is high. However, the crypto.setEngine() API can be used to bypass the permission model… | |
| Modificada | Media (4.2) | 0.47% | — | Nodejs Node.jsDebian Linux | 23/2/2023 | 17/6/2026 | An untrusted search path vulnerability exists in Node.js. <19.6.1, <18.14.1, <16.19.1, and <14.21.3 that could allow an attacker to search and potentially load ICU data when running with elevated privileges. | |
| Modificada | Alta (7.5) | 2.2% | — | Nodejs Node.js | 23/2/2023 | 17/6/2026 | A cryptographic vulnerability exists in Node.js <19.2.0, <18.14.1, <16.19.1, <14.21.3 that in some cases did does not clear the OpenSSL error stack after operations that may set it. This may lead to false positive errors during subsequent cryptographic operations that happen to be on the same thread. This in turn… | |
| Modificada | Alta (7.5) | 2.0% | — | Nodejs Node.js | 23/2/2023 | 17/6/2026 | A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who… | |
| Modificada | Alta (7.5) | 1.3% | — | Nodejs Undici | 16/2/2023 | 17/6/2026 | Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular expression used to normalize the… | |
| Modificada | Media (5.4) | 1.1% | — | Nodejs Node.jsNodejs Undici | 16/2/2023 | 17/6/2026 | Undici is an HTTP/1.1 client for Node.js. Starting with version 2.0.0 and prior to version 5.19.1, the undici library does not protect `host` HTTP header from CRLF injection vulnerabilities. This issue is patched in Undici v5.19.1. As a workaround, sanitize the `headers.host` string before passing to undici. | |
| Modificada | Alta (8.1) | 15% | — | Nodejs Node.jsDebian Linux | 5/12/2022 | 17/6/2026 | A OS Command Injection vulnerability exists in Node.js versions <14.21.1, <16.18.1, <18.12.1, <19.0.1 due to an insufficient IsAllowedHost check that can easily be bypassed because IsIPAddress does not properly check if an IP address is invalid before making DBS requests allowing rebinding attacks.The fix for this… | |
| Modificada | Media (6.5) | 2.7% | — | Nodejs Node.jsLlhttpSiemens Sinec INSDebian Linux | 5/12/2022 | 17/6/2026 | The llhttp parser in the http module in Node v18.7.0 does not correctly handle header fields that are not terminated with CLRF. This may result in HTTP Request Smuggling. | |
| Modificada | Crítica (9.1) | 1.9% | — | Nodejs Node.jsSiemens Sinec INSDebian Linux | 5/12/2022 | 17/6/2026 | A weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGen() in src/crypto/crypto_keygen.cc. There are two problems with this: 1) It does not check the return value, it assumes EntropySource() always succeeds, but it can (and sometimes… | |
| Modificada | Alta (7.5) | 92% | — | OpensslFedoraproject FedoraNodejs Node.js | 1/11/2022 | 17/6/2026 | A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed a malicious certificate or for an application to continue certificate verification despite failure… | |
| Modificada | Alta (7.5) | 91% | — | OpensslFedoraproject FedoraNetapp Clustered Data OntapNodejs Node.js | 1/11/2022 | 17/6/2026 | A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification and requires either a CA to have signed the malicious certificate or for the application to continue certificate verification despite… | |
| Modificada | Media (5.3) | 1.3% | — | Nodejs Undici | 15/8/2022 | 17/6/2026 | undici is an HTTP/1.1 client, written from scratch for Node.js.`=< undici@5.8.0` users are vulnerable to _CRLF Injection_ on headers when using unsanitized input as request headers, more specifically, inside the `content-type` header. Example: ``` import { request } from 'undici' const unsanitizedContentTypeInput =… | |
| Modificada | Crítica (9.8) | 1.8% | — | Nodejs Undici | 12/8/2022 | 17/6/2026 | undici is an HTTP/1.1 client, written from scratch for Node.js.`undici` is vulnerable to SSRF (Server-side Request Forgery) when an application takes in **user input** into the `path/pathname` option of `undici.request`. If a user specifies a URL such as `http://127.0.0.1` or `//127.0.0.1` ```js const undici =… | |
| Modificada | Media (6.5) | 0.72% | — | Nodejs Undici | 21/7/2022 | 17/6/2026 | Authorization headers are cleared on cross-origin redirect. However, cookie headers which are sensitive headers and are official headers found in the spec, remain uncleared. There are active users using cookie headers in undici. This may lead to accidental leakage of cookie to a 3rd-party site or a malicious attacker… | |
| Modificada | Media (6.5) | 1.4% | — | Nodejs Undici | 19/7/2022 | 17/6/2026 | undici is an HTTP/1.1 client, written from scratch for Node.js. It is possible to inject CRLF sequences into request headers in undici in versions less than 5.7.1. A fix was released in version 5.8.0. Sanitizing all HTTP headers from untrusted sources to eliminate `\r\n` is a workaround for this issue. |