Node.js

First CVE: Dec 11, 2017Active for: 9 years
18
CVEs Published
More CVEs Published than 37% of tracked CNAs
6.0
Avg CVEs / Year
More Avg CVEs / Year than 37% of tracked CNAs
7.2
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Node.js as a CNA, 100.0% affect products that Node.js develops as a vendor.

100.0%
Self-reported: 18Third-party: 0

Of all the CVEs published that affect products developed by Node.js, 7.5% are self-published by Node.js as a CNA.

92.5%
Self-published: 18Published by other CNAs: 221

Trends Over Time

The number and severity of CVEs published by Node.js over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 11, 2017
8 years ago
Most Recent CVE
Mar 28, 2019
2,675 days ago

Top CVEs

All CVEs published by Node.js as a CNA, regardless of affected vendor or product.

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Slowloris HTTP Denial of Service: An attacker can cause a Denial of Service (DoS) by sending headers very
Nov 28, 20187.547NONO
In Node.js including 6.x before 6.17.0, 8.x before 8.15.1, 10.x before 10.15.2, and 11.x before 11.10.1, an attacker can cause a Denial of Service (DoS) by establishing an HTTP or
Mar 28, 20197.533NONO
The Node.js inspector, in 6.x and later is vulnerable to a DNS rebinding attack which could be exploited to perform remote code execution. An attack is possible from malicious webs
May 17, 20188.833NONO
Node.js was affected by OpenSSL vulnerability CVE-2017-3737 in regards to the use of SSL_read() due to TLS handshake failure. The result was that an active network attacker could s
Dec 11, 20179.130NONO
Node.js: All versions prior to Node.js 6.15.0, 8.14.0, 10.14.0 and 11.3.0: Denial of Service with large HTTP headers: By using a combination of many requests with maximum sized hea
Nov 28, 20187.529NONO
Node.js: All versions prior to Node.js 6.15.0: Debugger port 5858 listens on any interface by default: When the debugger is enabled with `node --debug` or `node debug`, it listens
Nov 28, 20188.128NONO
In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`
Aug 21, 20187.528NONO
Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementatio
Jun 13, 20187.528NONO
All versions of Node.js 9.x and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node process which provides an http serve
Jun 13, 20187.528NONO
All versions of Node.js 8.x, 9.x, and 10.x are vulnerable and the severity is HIGH. An attacker can cause a denial of service (DoS) by causing a node server providing an http2 serv
Jun 13, 20187.528NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA18 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low16 (88.9%)
High2 (11.1%)
Unknown0 (0.0%)
User Interaction
None16 (88.9%)
Unknown0 (0.0%)
Required2 (11.1%)
Privileges Required
Low1 (5.6%)
High0 (0.0%)
None17 (94.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (18 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Node.js as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Node.js as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs