Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

node-fetch — Vulnerabilities & Security Advisories 3

Browse all 3 CVE security advisories affecting node-fetch. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Node-fetch is a lightweight HTTP client for Node.js, enabling server-side data fetching and API interactions. Historically, it has been susceptible to remote code execution (RCE) and cross-site scripting (XSS) vulnerabilities, often due to improper input validation or insecure handling of URLs and headers. Notable security characteristics include its widespread adoption in serverless environments and dependency chains, which amplifies potential impact. A major incident in 2020 revealed a critical RCE flaw (CVE-2021-22963) through improper redirect handling, affecting numerous applications. Despite these issues, node-fetch remains a core tool for HTTP requests, requiring developers to implement strict input validation and keep dependencies updated to mitigate risks.

Found 2 results / 3Clear Filters
Top products by node-fetch: node-fetch/node-fetch node-fetch

This page lists every published CVE security advisory associated with node-fetch. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.