vciy

CVEs we hold for Nodejs

Records whose assigning authority named Nodejs as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-58045no title heldnodejs node
CVE-2026-58044no title heldnodejs node
CVE-2026-58043no title heldnodejs node
CVE-2026-58042no title heldnodejs node
CVE-2026-58041no title heldnodejs node
CVE-2026-58040no title heldnodejs node
CVE-2026-58039no title heldnodejs node
CVE-2026-56850no title heldnodejs node
CVE-2026-56848no title heldnodejs node
CVE-2026-56847no title heldnodejs node
CVE-2026-56846no title heldnodejs node
CVE-2026-48937no title heldnodejs node
CVE-2026-48936no title heldnodejs node
CVE-2026-48935no title heldnodejs node
CVE-2026-48934no title heldnodejs node
CVE-2026-48933no title heldnodejs node
CVE-2026-48932no title heldnodejs node
CVE-2026-48931no title heldnodejs node
CVE-2026-48930no title heldnodejs node
CVE-2026-48928no title heldnodejs node
CVE-2026-48619no title heldnodejs node
CVE-2026-48618no title heldnodejs node
CVE-2026-48617no title heldnodejs node
CVE-2026-48615no title heldnodejs node
CVE-2026-22036Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to…nodejs undici
CVE-2026-21717no title heldnodejs node
CVE-2026-21716no title heldnodejs node
CVE-2026-21715no title heldnodejs node
CVE-2026-21714no title heldnodejs node
CVE-2026-21713no title heldnodejs node
CVE-2026-21712no title heldnodejs node
CVE-2026-21711no title heldnodejs node
CVE-2026-21710no title heldnodejs node
CVE-2026-21637no title heldnodejs node
CVE-2026-21636no title heldnodejs node
CVE-2025-59466no title heldnodejs node
CVE-2025-59465no title heldnodejs node
CVE-2025-59464no title heldnodejs node
CVE-2025-55132no title heldnodejs node
CVE-2025-55131no title heldnodejs node
CVE-2025-55130no title heldnodejs node
CVE-2025-47279undici Denial of Service attack via bad certificate datanodejs undici
CVE-2025-27210no title heldnodejs
CVE-2025-27209no title heldnodejs node
CVE-2025-23167no title heldnodejs node
CVE-2025-23166no title heldnodejs node
CVE-2025-23165no title heldnodejs node
CVE-2025-23085no title heldNodeJS Node
CVE-2025-23084no title heldNodeJS Node
CVE-2025-23083no title heldNodeJS Node
CVE-2025-22150Undici Uses Insufficiently Random Valuesnodejs undici
CVE-2024-38372Undici vulnerable to data leak when using response.arrayBuffer()nodejs undici
CVE-2024-37372no title heldNodeJS Node
CVE-2024-36138no title heldNodeJS Node
CVE-2024-36137no title heldNodeJS Node
CVE-2024-30261Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrectnodejs undici
CVE-2024-30260Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipelinenodejs undici
CVE-2024-27983no title heldNodeJS Node
CVE-2024-27982no title heldNodeJS Node
CVE-2024-27980no title heldNodeJS Node
CVE-2024-24758Proxy-Authorization header not cleared on cross-origin redirect in fetch in Undicinodejs undici
CVE-2024-24750Backpressure request ignored in fetch() in Undicinodejs undici
CVE-2024-22025no title heldNodeJS Node
CVE-2024-22020no title heldNodeJS Node
CVE-2024-22019no title heldNodeJS Node
CVE-2024-22018no title heldNodeJS Node
CVE-2024-22017no title heldNodeJS Node
CVE-2024-21896no title heldNodeJS Node
CVE-2024-21892no title heldNodeJS Node
CVE-2024-21891no title heldNodeJS Node
CVE-2024-21890no title heldNodeJS Node
CVE-2023-46809no title heldNodeJS Node
CVE-2023-45143Undici's cookie header not cleared on cross-origin redirect in fetchnodejs undici
CVE-2023-39333no title heldNodeJS Node
CVE-2023-39332no title heldNodeJS Node
CVE-2023-39331no title heldNodeJS Node
CVE-2023-38552no title heldNodeJS Node
CVE-2023-32559no title heldNodeJS Node
CVE-2023-32558no title heldNodeJS Node
CVE-2023-32006no title heldNodeJS Node
CVE-2023-32005no title heldNodeJS Node
CVE-2023-32004no title heldNodeJS Node
CVE-2023-32003no title heldNodeJS Node
CVE-2023-32002no title heldNodeJS Node
CVE-2023-30590no title heldNodeJS Node
CVE-2023-30589no title heldNodeJS Node
CVE-2023-30588no title heldNodeJS Node
CVE-2023-30587no title heldNodeJS Node
CVE-2023-30586no title heldNodeJS Node
CVE-2023-30585no title heldNodeJS Node
CVE-2023-30584no title heldNodeJS Node
CVE-2023-30583no title heldNodeJS Node
CVE-2023-30582no title heldNodeJS Node
CVE-2023-30581no title heldNodeJS Node
CVE-2023-24807Undici vulnerable to Regular Expression Denial of Service in Headersnodejs undici
CVE-2023-23936CRLF Injection in Nodejs ‘undici’ via hostnodejs undici
CVE-2023-23920no title heldNodeJS Node
CVE-2023-23919no title heldNodeJS Node
CVE-2023-23918no title heldNodeJS Node
CVE-2022-43548no title heldNodeJS Node
CVE-2022-35949`undici.request` vulnerable to SSRF using absolute URL on `pathname`nodejs undici
CVE-2022-35948CRLF Injection in Nodejs ‘undici’ via Content-Typenodejs undici
CVE-2022-35256no title heldNodeJS Node
CVE-2022-35255no title heldNodeJS Node
CVE-2022-32223no title heldNodeJS Node
CVE-2022-32222no title heldNodeJS Node
CVE-2022-32215no title heldNodeJS Node
CVE-2022-32214no title heldNodeJS Node
CVE-2022-32213no title heldNodeJS Node
CVE-2022-32212no title heldNodeJS Node
CVE-2022-31151Uncleared cookies on cross-host/cross-origin redirect in undicinodejs undici
CVE-2022-31150CRLF injection in request headersnodejs undici
CVE-2022-21824no title heldNodeJS Node
CVE-2021-44533no title heldNodeJS Node
CVE-2021-44532no title heldNodeJS Node
CVE-2021-44531no title heldNodeJS Node
CVE-2021-22960no title heldNodeJS Node
CVE-2021-22959no title heldNodeJS Node
CVE-2021-22940no title heldNodeJS Node
CVE-2021-22939no title heldNodeJS Node
CVE-2021-22931no title heldNodeJS Node
CVE-2021-22930no title heldNodeJS Node
CVE-2021-22921no title heldNodeJS Node
CVE-2021-22918no title heldNodeJS Node
CVE-2021-22884no title heldNodeJS Node
CVE-2021-22883no title heldNodeJS Node
CVE-2020-8287no title heldNodeJS Node
CVE-2020-8277no title heldNodeJS Node
CVE-2020-8265no title heldNodeJS Node
CVE-2020-8252no title heldNodeJS Node
CVE-2020-8251no title heldNodeJS Node
CVE-2020-8201no title heldNodeJS Node
CVE-2019-15606no title heldNodeJS Node
CVE-2019-15605no title heldNodeJS Node
CVE-2019-15604no title heldNodeJS Node
CVE-2019-10196no title heldn/a nodejs-http-proxy-agent
CVE-2018-1109no title heldn/a nodejs-braces
CVE-2018-1107no title heldn/a nodejs-is-my-json-valid

138 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.