CVEs we hold for Nodejs
Records whose assigning authority named Nodejs as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-22036Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to…nodejs undici
CVE-2024-30261Undici's fetch with integrity option is too lax when algorithm is specified but hash value is in incorrectnodejs undici
CVE-2024-30260Undici's Proxy-Authorization header not cleared on cross-origin redirect for dispatch, request, stream, pipelinenodejs undici
CVE-2024-24758Proxy-Authorization header not cleared on cross-origin redirect in fetch in Undicinodejs undici
138 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.