Vulnerability index

Browse CVEs

112 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Node.js HIGH 7.4
CVE-2020-8201EPSS 5%

Node.js < 12.18.4 and < 14.11 can be exploited to perform HTTP desync attacks and deliver malicious payloads to unsuspecting users. The payloads can …

Fix: 12.18.4 / 14.11.0+
Fix from $1,950 2020-09-18
Node.js HIGH 8.1
CVE-2020-8174EPSS 8%

napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0.

Fix: 10.21.0 / 12.18.0+
Fix from $1,950 2020-07-24
Node.js HIGH 7.4
CVE-2020-8172EPSS 6%

TLS session reuse can lead to host certificate verification bypass in node version < 12.18.0 and < 14.4.0.

Fix: 12.18.0 / 14.4.0+
Fix from $1,950 2020-06-08
Node.js HIGH 8.1
CVE-2014-9748

The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv before 1.7.4 does not properly prevent threads from releasing the loc…

Fix: 0.10.46 / 0.12.15+
Fix from $1,950 2020-02-11
Node.js CRITICAL 9.8
CVE-2019-15605EPSS 57%

HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed

Fix: 10.19.0 / 12.15.0+
Fix from $2,300 2020-02-07
Node.js CRITICAL 9.8
CVE-2019-15606EPSS 20%

Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons

Fix: 10.19.0 / 12.15.0+
Fix from $2,300 2020-02-07
Node.js HIGH 7.5
CVE-2019-15604EPSS 20%

Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate

Fix: 10.19.0 / 12.15.0+
Fix from $1,950 2020-02-07
Node.js HIGH 7.5
CVE-2018-12116

Node.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized user-provided Unicod…

Fix: 6.15.0 / 8.14.0+
Fix from $1,950 2018-11-28
Node.js HIGH 7.5
CVE-2018-12121EPSS 10%

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many …

Fix: 6.15.0 / 8.14.0+
Fix from $1,950 2018-11-28
Node.js HIGH 7.5
CVE-2018-12122EPSS 41%

Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Servic…

Fix: 6.15.1 / 8.14.0+
Fix from $1,950 2018-11-28
Node.js HIGH 7.5
CVE-2018-12115EPSS 8%

In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'…

Fix: 6.14.4 / 8.11.4+
Fix from $1,950 2018-08-21
Node.js MEDIUM 6.5
CVE-2017-16024

The sync-exec module is used to simulate child_process.execSync in node versions <0.11.9. Sync-exec uses tmp directories as a buffer before returning…

Fix: 0.11.9+
Fix from $1,600 2018-06-04
Node.js HIGH 7.5
CVE-2018-1000168EPSS 11%

nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20 vulnerability in ALTSVC frame handling that can result …

Fix: 10.4.1+
Fix from $1,950 2018-05-08
Node.js MEDIUM 6.5
CVE-2015-2927

node 0.3.2 and URONode before 1.0.5r3 allows remote attackers to cause a denial of service (bandwidth consumption).

Fix: after 1.0.5
Fix from $1,600 2017-09-20
Node.js HIGH 7.5
CVE-2017-1000381

The c-ares function `ares_parse_naptr_reply()`, which is used for parsing NAPTR responses, could be triggered to read memory outside of the given inp…

Fix: 4.8.4 / 6.11.1+
Fix from $1,950 2017-07-07
Node.js MEDIUM 5.9
CVE-2016-7099

The tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properl…

Patch available
Fix from $1,600 2016-10-10
Node.js MEDIUM 6.1
CVE-2016-5325

CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and …

Patch available
Fix from $1,600 2016-10-10
Node.js HIGH 7.5
CVE-2016-3956EPSS 7%

The CLI in npm before 2.15.1 and 3.x before 3.8.3, as used in Node.js 0.10 before 0.10.44, 0.12 before 0.12.13, 4 before 4.4.2, and 5 before 5.10.0, …

Fix: 2.15.1 / 3.8.3+
Fix from $1,950 2016-07-02
Node.js HIGH 7.5
CVE-2015-5380

The Utf8DecoderBase::WriteUtf16Slow function in unicode-decoder.cc in Google V8, as used in Node.js before 0.12.6, io.js before 1.8.3 and 2.x before …

Fix: after 1.8.2
Fix from $1,950 2015-07-09
Node.js MEDIUM 5.0
CVE-2014-5256

Node.js 0.8 before 0.8.28 and 0.10 before 0.10.30 does not consider the possibility of recursive processing that triggers V8 garbage collection in co…

Patch available
Fix from $1,600 2014-09-05
Node.js MEDIUM 5.0
CVE-2013-4450EPSS 37%

The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to cause a denial of service (memory and CPU consump…

Patch available
Fix from $1,600 2013-10-21
Node.js MEDIUM 6.4
CVE-2012-2330

The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allo…

Fix: after 0.6.16
Fix from $1,600 2012-08-13