Node.js undici Vulnerabilities
CVE security advisories and vulnerability history for undici by Node.js.
CVE security advisories and vulnerability history for undici by Node.js.
Last updated
Node.js undici has 35 published CVE records since 2022, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 10 have a known public exploit. The average CVSS base score across scored CVEs is 6.3.
This page aggregates every publicly disclosed vulnerability (CVE) affecting Node.js undici, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
How the CVSS severity of Node.js undici's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of Node.js undici's CVEs are currently listed in CISA's KEV catalog.
Public exploits
10
10 of Node.js undici's CVEs have a known public exploit available.
Browse every Node.js undici version named in a CVE, then pick one to see only the CVEs that affect it.
The CWE weakness categories most often found in Node.js undici CVEs. Follow any weakness for its full explanation.
How many Node.js undici CVEs were published each year.
Browse vulnerabilities for other products by Node.js.
Common questions about Node.js undici vulnerabilities.
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Monitor new Node.js undici vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.
35 CVEs
Showing 30 of 35