Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

NodeJS — Vulnerabilities & Security Advisories 134

Browse all 134 CVE security advisories affecting NodeJS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Node.js is a server-side JavaScript runtime environment primarily used for building scalable network applications and APIs. Its event-driven, non-blocking I/O architecture makes it popular for real-time services, yet this design introduces specific security challenges. Historically, the platform has been susceptible to Remote Code Execution (RCE) vulnerabilities, often stemming from prototype pollution or improper input validation in core modules. Cross-Site Scripting (XSS) and server-side request forgery (SSRF) are also frequent issues, particularly when handling untrusted user data or integrating with third-party libraries. With over 111 recorded Common Vulnerabilities and Exposures (CVEs), the ecosystem’s reliance on numerous npm packages amplifies supply chain risks. Notable incidents have included critical flaws in the HTTP parser and DNS resolution mechanisms, highlighting the necessity for rigorous dependency auditing and timely patching to mitigate exploitation of these systemic weaknesses in production environments.

Found 119 results / 134Clear Filters
Top products by NodeJS: Node undici
CVE IDTitleCVSSSeverityPublished
CVE-2026-56848 Node.js 资源管理错误漏洞 — nodeCWE-416--2026-08-04
CVE-2026-56846 Node.js 资源管理错误漏洞 — nodeCWE-400--2026-08-04
CVE-2026-58044 nodejs node 输入验证错误漏洞 — nodeCWE-444--2026-08-04
CVE-2026-58042 nodejs node 资源管理错误漏洞 — nodeCWE-400--2026-08-04
CVE-2026-58041 Node.js 竞争条件问题漏洞 — nodeCWE-367--2026-08-04
CVE-2026-58045 nodejs node 资源管理错误漏洞 — nodeCWE-400--2026-08-04
CVE-2026-58039 Node.js 权限许可和访问控制问题漏洞 — nodeCWE-284--2026-07-31
CVE-2026-56847 nodejs node 处理逻辑错误漏洞 — nodeCWE-1119--2026-07-30
CVE-2026-56850 nodejs node 授权问题漏洞 — nodeCWE-287--2026-07-30
CVE-2026-58040 nodejs node 安全漏洞 — node--2026-07-30
CVE-2026-58043 nodejs node 权限许可和访问控制问题漏洞 — nodeCWE-284--2026-07-30
CVE-2026-48936 nodejs Node.js 权限许可和访问控制问题漏洞 — nodeCWE-284--2026-06-26
CVE-2026-48930 nodejs Node.js 权限许可和访问控制问题漏洞 — nodeCWE-284--2026-06-26
CVE-2026-48928 nodejs Node.js 权限许可和访问控制问题漏洞 — nodeCWE-284--2026-06-26
CVE-2026-48615 nodejs node.js 信息泄露漏洞 — nodeCWE-359--2026-06-26
CVE-2026-48934 nodejs Node.js 安全漏洞 — node--2026-06-26
CVE-2026-48619 nodejs Node.js 资源管理错误漏洞 — nodeCWE-400--2026-06-26
CVE-2026-48935 nodejs Node.js 权限许可和访问控制问题漏洞 — nodeCWE-276--2026-06-26
CVE-2026-48618 nodejs Node.js 输入验证错误漏洞 — nodeCWE-176--2026-06-26
CVE-2026-48933 nodejs Node.js 数字错误漏洞 — nodeCWE-190--2026-06-26
CVE-2026-48931 nodejs node 竞争条件问题漏洞 — nodeCWE-367--2026-06-22
CVE-2026-48937 Node.js 资源管理错误漏洞 — nodeCWE-400--2026-06-18
CVE-2026-48617 Node.js 权限许可和访问控制问题漏洞 — nodeCWE-284--2026-06-18
CVE-2026-21711 Node.js 安全漏洞 — node 9.9AICriticalAI2026-03-30
CVE-2026-21715 Node.js 安全漏洞 — node 6.5AIMediumAI2026-03-30
CVE-2026-21716 Node.js 安全漏洞 — node 8.8AIHighAI2026-03-30
CVE-2026-21710 Node.js 安全漏洞 — node 7.5AIHighAI2026-03-30
CVE-2026-21717 Node.js 安全漏洞 — node 5.3AIMediumAI2026-03-30
CVE-2026-21714 Node.js 安全漏洞 — node 7.5AIHighAI2026-03-30
CVE-2026-21713 Node.js 安全漏洞 — node 3.7AILowAI2026-03-30

This page lists every published CVE security advisory associated with NodeJS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.