Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

NodeJS — Vulnerabilities & Security Advisories 135

Browse all 135 CVE security advisories affecting NodeJS. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Node.js is a server-side JavaScript runtime environment primarily used for building scalable network applications and APIs. Its event-driven, non-blocking I/O architecture makes it popular for real-time services, yet this design introduces specific security challenges. Historically, the platform has been susceptible to Remote Code Execution (RCE) vulnerabilities, often stemming from prototype pollution or improper input validation in core modules. Cross-Site Scripting (XSS) and server-side request forgery (SSRF) are also frequent issues, particularly when handling untrusted user data or integrating with third-party libraries. With over 111 recorded Common Vulnerabilities and Exposures (CVEs), the ecosystem’s reliance on numerous npm packages amplifies supply chain risks. Notable incidents have included critical flaws in the HTTP parser and DNS resolution mechanisms, highlighting the necessity for rigorous dependency auditing and timely patching to mitigate exploitation of these systemic weaknesses in production environments.

Found 120 results / 135 Clear Filters
Top products by NodeJS: Node undici
CVE ID Title CVSS Severity Published
CVE-2022-35256 Node.js 环境问题漏洞 — Node CWE-444 6.5 - 2022-12-05
CVE-2022-32223 Node.js 代码问题漏洞 — Node CWE-427 7.8 - 2022-07-14
CVE-2022-32212 Node.js 操作系统命令注入漏洞 — Node CWE-284 8.1 - 2022-07-14
CVE-2022-32213 Node.js 环境问题漏洞 — Node CWE-444 6.5 - 2022-07-14
CVE-2022-32214 IBM Answer Retrieval for Watson Discovery On Prem 环境问题漏洞 — Node CWE-444 6.5 - 2022-07-14
CVE-2022-32215 Node.js 环境问题漏洞 — Node CWE-444 6.5 - 2022-07-14
CVE-2022-32222 Node.js 代码问题漏洞 — Node CWE-310 8.2 - 2022-07-14
CVE-2021-44533 nodejs 信任管理问题漏洞 — Node CWE-295 7.5 - 2022-02-24
CVE-2021-44532 nodejs 信任管理问题漏洞 — Node CWE-296 5.3 - 2022-02-24
CVE-2021-44531 nodejs 信任管理问题漏洞 — Node CWE-295 7.5 - 2022-02-24
CVE-2022-21824 nodejs 代码注入漏洞 — Node CWE-471 8.2 - 2022-02-24
CVE-2021-22959 Nodejs Core 环境问题漏洞 — Node CWE-444 6.5 - 2021-11-15
CVE-2021-22960 nodejs 环境问题漏洞 — Node CWE-444 6.5 - 2021-11-03
CVE-2021-22930 nodejs 资源管理错误漏洞 — Node CWE-416 7.5 - 2021-10-07
CVE-2021-22931 node core 输入验证错误漏洞 — Node CWE-170 8.8 - 2021-08-16
CVE-2021-22939 node core 信任管理问题漏洞 — Node CWE-295 5.3 - 2021-08-16
CVE-2021-22940 node core 资源管理错误漏洞 — Node CWE-416 7.5 - 2021-08-16
CVE-2021-22921 Nodejs 安全漏洞 — Node CWE-732 7.8 - 2021-07-12
CVE-2021-22918 nodejs 缓冲区错误漏洞 — Node CWE-125 8.2 - 2021-07-12
CVE-2021-22883 nodejs 资源管理错误漏洞 — Node CWE-400 7.5 - 2021-03-03
CVE-2021-22884 Nodejs 安全漏洞 — Node CWE-350 8.1 - 2021-03-03
CVE-2020-8265 nodejs 资源管理错误漏洞 — Node CWE-416 8.1 - 2021-01-06
CVE-2020-8287 nodejs 环境问题漏洞 — Node CWE-444 6.5 - 2021-01-06
CVE-2020-8277 Oracle GraalVM 资源管理错误漏洞 — Node CWE-400 7.5 - 2020-11-19
CVE-2020-8201 Node.js 环境问题漏洞 — Node CWE-444 7.4 - 2020-09-18
CVE-2020-8252 Node.js 缓冲区错误漏洞 — Node CWE-120 9.8 - 2020-09-18
CVE-2020-8251 Node.js 资源管理错误漏洞 — Node CWE-400 7.5 - 2020-09-18
CVE-2019-15606 Joyent Node.js 安全漏洞 — Node CWE-20 9.8 - 2020-02-07
CVE-2019-15604 Node.js 信任管理问题漏洞 — Node CWE-295 7.5 - 2020-02-07
CVE-2019-15605 Joyent Node.js 环境问题漏洞 — Node CWE-444 9.1 - 2020-02-07

This page lists every published CVE security advisory associated with NodeJS. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.