Node.js Vulnerabilities
CVE security advisories and vulnerability history for Node.js.
CVE security advisories and vulnerability history for Node.js.
Node.js has 27 published CVE records since 2017, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 1 have a known public exploit. The average CVSS base score across scored CVEs is 7.2.
This page aggregates every publicly disclosed vulnerability (CVE) affecting Node.js products, with severity breakdowns, the most-affected products, the most common weakness types, and the latest disclosures.
A quick read on Node.js's vulnerability posture, as a share of its 27 published CVEs.
across 27 scored CVEs
21 of 27 scored
0 of 27 CVEs
1 of 27 CVEs
27 of 27 CVEs
How the CVSS severity of Node.js's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of Node.js's CVEs are currently listed in CISA's KEV catalog.
Public exploits
1
One of Node.js's CVEs has a known public exploit available.
The Node.js products with the most published CVEs. Follow any product to browse its versions and vulnerabilities.
The CWE weakness categories most often found in Node.js CVEs. Follow any weakness for its full explanation.
The CVE Numbering Authorities that publish Node.js CVE records.
How many Node.js CVEs were published each year.
The most recently disclosed vulnerabilities affecting Node.js.
Browse vulnerabilities for other tracked vendors.
Common questions about Node.js vulnerabilities.
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Monitor new Node.js vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.
Track new Node.js CVEs as they are disclosed and get AI-written analysis and remediation guidance.
Monitor Node.js CVEs