nodejs node.js
165 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
pskCallback or `HTTP/2 HEADERS frame with oversized, invalid HPACK data can cause Node.js to crash by triggering an unhandled `TLSX.509 certificate fields to UTF-8 without freeing the alfutimes() even when th--allow-fs-read and --allow-fs-write restrictions using cranode:fs functions allow specifying paths as either strings or Uint8Array objects. In Node.js environments, the `Bufferprocess.binding() can bypass the permission model through path traversal. This vulnerability affModule._load() can bypass the policy mechanism and require modules outside of the policy.json definition for a givenmodule.constructor.createRequire() can bypass the policy mechanism and require modules outside of the policy.json deffs.mkdtemp() and fs.mkdtempSync() can be used to bypass the permission model check using a path traversal attack. This flaw arBuffer.alloc() to return uninitialized memoContent-Length header, allowing input such as `Content-'path' module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) vector. Theares_parse_naptr_reply(), which is used for parsing NAPTR responses, could be triggered to read memory outsi