Vulnerabilidades en nodejs

134 resultados
Análisis Vexday

Node.js apresenta 48 vulnerabilidades catalogadas na base, com 12 divulgadas nos últimos 90 dias, indicando atividade recente de descoberta de falhas. Nenhuma CVE está sob exploração ativa (KEV) nem classificada como crítica, reduzindo o risco imediato. A fraqueza dominante (CWE-284) aponta problemas de controle de acesso, sugerindo que a maior parte dos riscos reside em cenários de escalação de privilégio ou autorização inadequada.

CVE-2022-35255CRITICALA weak randomness in WebCrypto keygen vulnerability exists in Node.js 18 due to a change with EntropySource() in SecretKeyGenTraits::DoKeyGeEPSS 1.9%CVE-2023-39332Various `node:fs` functions allow specifying paths as either strings or `Uint8Array` objects. In Node.js environments, the `Buffer` class exEPSS 1.8%CVE-2023-32004HIGHA vulnerability has been discovered in Node.js version 20, specifically within the experimental permission model. This flaw relates to improEPSS 1.8%CVE-2022-32223Node.js is vulnerable to Hijack Execution Flow: DLL Hijacking under certain conditions on Windows platforms.This vulnerability can be exploiEPSS 1.7%CVE-2025-55130HIGHA flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relativEPSS 1.6%CVE-2023-32559HIGHA privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use EPSS 1.5%CVE-2023-32558The use of the deprecated API `process.binding()` can bypass the permission model through path traversal. This vulnerability affects all uEPSS 1.5%CVE-2023-30585A vulnerability has been identified in the Node.js (.msi version) installation process, specifically affecting Windows users who install NodEPSS 1.5%CVE-2023-30590The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generEPSS 1.5%CVE-2023-32002CRITICALThe use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module. TEPSS 1.4%CVE-2024-27980HIGHDue to the improper handling of batch files in child_process.spawn / child_process.spawnSync, a malicious command line argument can inject aEPSS 1.4%CVE-2025-23084MEDIUMA vulnerability has been identified in Node.js, specifically affecting the handling of drive names in the Windows environment. Certain Node.EPSS 1.4%CVE-2022-31150MEDIUMCRLF injection in request headersEPSS 1.4%CVE-2022-35949MEDIUM`undici.request` vulnerable to SSRF using absolute URL on `pathname`EPSS 1.4%CVE-2023-30586HIGHA privilege escalation vulnerability exists in Node.js 20 that allowed loading arbitrary OpenSSL engines when the experimental permission moEPSS 1.3%CVE-2025-23085MEDIUMA memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid hEPSS 1.3%CVE-2023-39331HIGHA previously disclosed vulnerability (CVE-2023-30584) was patched insufficiently in commit 205f1e6. The new path traversal vulnerability ariEPSS 1.3%CVE-2024-22025MEDIUMA vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetEPSS 1.3%CVE-2023-24807HIGHUndici vulnerable to Regular Expression Denial of Service in HeadersEPSS 1.3%CVE-2023-46809HIGHNode.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched areEPSS 1.3%