Vulnerability search
Batch lookup →60 matches
- CVE-2026-21710A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received…2 sources· cvehighEPSS 25%117.57.597.8%2026-03-30 20:16 UTC
- CVE-2025-59465A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash…2 sources· cvehighEPSS 3.8%106.27.589.2%2026-01-20 21:16 UTC
- CVE-2016-9841inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by…2 sources· cvecriticalEPSS 7.5%105.29.894.1%2017-05-23 04:29 UTC
- CVE-2016-9842The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have…2 sources· cvehighEPSS 5.2%98.98.891.9%2017-05-23 04:29 UTC
- CVE-2016-9840inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by…2 sources· cvehighEPSS 4.8%98.58.891.3%2017-05-23 04:29 UTC
- CVE-2016-2183The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols…2 sources· cvehighEPSS 96%97.47.599.9%2016-09-01 00:59 UTC
- CVE-2014-0224OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict…2 sources· cvehighEPSS 95%96.97.499.9%2014-06-05 21:55 UTC
- CVE-2025-55130A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and…2 sources· cvehighEPSS 1.7%95.87.175.1%2026-01-20 21:16 UTC
- CVE-2019-5737In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before…2 sources· cvehighEPSS 16%95.57.596.7%2019-03-28 17:29 UTC
- CVE-2018-1000168nghttp2 version >= 1.10.0 and nghttp2 <= v1.31.0 contains an Improper Input Validation CWE-20…2 sources· cvehighEPSS 11%94.87.595.5%2018-05-08 15:29 UTC
- CVE-2026-1526The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory…2 sources· cvehighEPSS 1.1%93.47.565.0%2026-03-12 21:16 UTC
- CVE-2019-5739Keep-alive HTTP and HTTPS connections can remain open and inactive for up to 2 minutes in Node.js…2 sources· cvehighEPSS 5.1%92.67.591.8%2019-03-28 17:29 UTC
- CVE-2026-12151A flaw was found in undici.2 sources· cvehighEPSS 0.8%92.37.554.1%2026-06-17 17:16 UTC
- CVE-2026-2229ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper…2 sources· cvehighEPSS 0.9%88.57.556.5%2026-03-12 21:16 UTC
- CVE-2019-1559If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to…2 sources· cvemediumEPSS 17%87.65.996.9%2019-02-27 23:29 UTC
- CVE-2026-9697Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5…2 sources· cvehighEPSS 0.5%82.47.438.5%2026-06-17 18:18 UTC
- CVE-2026-1528ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large…2 sources· cvehighEPSS 0.5%78.77.540.2%2026-03-12 21:16 UTC
- CVE-2026-6734Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different…2 sources· cvehighEPSS 0.3%76.47.527.6%2026-06-17 18:18 UTC
- CVE-2026-21714A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0…2 sources· cvemediumEPSS 0.4%67.15.338.0%2026-03-30 20:16 UTC
- CVE-2026-21713A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating…2 sources· cvemediumEPSS 0.4%66.45.931.8%2026-03-30 20:16 UTC
- CVE-2013-4450The HTTP server in Node.js 0.10.x before 0.10.21 and 0.8.x before 0.8.26 allows remote attackers to…2 sources· cvenoneEPSS 37%59.00.098.4%2013-10-21 17:55 UTC
- CVE-2026-16729undici's setCookie function does not fully sanitize cookie attributes.2 sources· cvemediumEPSS 0.2%57.46.58.8%2026-07-29 17:16 UTC
- CVE-2013-6668Multiple unspecified vulnerabilities in Google V8 before 3.24.35.10, as used in Google Chrome…2 sources· cvenoneEPSS 5.4%55.30.092.2%2014-03-05 05:11 UTC
- CVE-2014-5256Node.js 0.8 before 0.8.28 and 0.10 before 0.10.30 does not consider the possibility of recursive…2 sources· cvenoneEPSS 3.3%52.50.087.6%2014-09-05 17:55 UTC
- CVE-2013-2882Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial…2 sources· cvenoneEPSS 2.9%51.50.085.9%2013-07-31 13:20 UTC