OpenJS Foundation
First CVE: Jul 17, 2025Active for: 1 year
63
CVEs Published
More CVEs Published than 63% of tracked CNAs
31.5
Avg CVEs / Year
More Avg CVEs / Year than 77% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 46% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Trends Over Time
The number and severity of CVEs published by OpenJS Foundation over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2025
12 months ago
Most Recent CVE
Jul 23, 2026
1 day ago
Top CVEs
All CVEs published by OpenJS Foundation as a CNA, regardless of affected vendor or product.
63 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-16117CRITICAL Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for ro | Jul 18, 2026 | 10.0 | 44 | NO | NO |
CVE-2026-4800CRITICAL Impact:
The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation | Mar 31, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-14198CRITICAL @fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching middleware paths, while Fastify's underlying router preserves | Jul 1, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-6556CRITICAL @fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays of paths an | Jun 30, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-15631HIGH Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSo | Jul 18, 2026 | 8.7 | 38 | NO | NO |
CVE-2026-16158HIGH Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter | Jul 18, 2026 | 8.7 | 38 | NO | NO |
CVE-2026-6734HIGH Impact:
When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requ | Jun 17, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-13676HIGH fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the | Jun 29, 2026 | 7.5 | 37 | NO | NO |
CVE-2026-14181HIGH @fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when incoming request paths contain malformed percent-encoded se | Jul 1, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-12151HIGH Impact:
The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malici | Jun 17, 2026 | 7.5 | 36 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA63 CVEs
32%
48%
16%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (3.2%)
Network60 (95.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.6%)
Attack Complexity
Low50 (79.4%)
High13 (20.6%)
Unknown0 (0.0%)
User Interaction
None58 (92.1%)
Unknown0 (0.0%)
Required4 (6.3%)
Privileges Required
Low4 (6.3%)
High1 (1.6%)
None58 (92.1%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (63 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by OpenJS Foundation as a CNA.
Media Mentions
Media articles that mention a CVE ID published by OpenJS Foundation as a CNA — matched by CVE ID, not by organization name.