OpenJS Foundation

First CVE: Jul 17, 2025Active for: 1 year
63
CVEs Published
More CVEs Published than 63% of tracked CNAs
31.5
Avg CVEs / Year
More Avg CVEs / Year than 77% of tracked CNAs
7.0
Avg CVSS Score
Higher Avg CVSS Score than 46% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by OpenJS Foundation over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 17, 2025
12 months ago
Most Recent CVE
Jul 23, 2026
1 day ago

Top CVEs

All CVEs published by OpenJS Foundation as a CNA, regardless of affected vendor or product.

63 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's router URL-decodes paths for ro
Jul 18, 202610.044NONO
Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHSA-35jh-r3h4-6jhm) added validation for the variable option in _.template but did not apply the same validation
Mar 31, 20269.842NONO
@fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching middleware paths, while Fastify's underlying router preserves
Jul 1, 20269.139NONO
@fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays of paths an
Jun 30, 20269.139NONO
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSo
Jul 18, 20268.738NONO
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter
Jul 18, 20268.738NONO
Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requ
Jun 17, 20268.838NONO
fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the
Jun 29, 20267.537NONO
@fastify/middie versions 9.1.0 through 9.3.2 fail to guard the URL normalization step used by the standalone engine when incoming request paths contain malformed percent-encoded se
Jul 1, 20267.536NONO
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malici
Jun 17, 20267.536NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA63 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local2 (3.2%)
Network60 (95.2%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (1.6%)
Attack Complexity
Low50 (79.4%)
High13 (20.6%)
Unknown0 (0.0%)
User Interaction
None58 (92.1%)
Unknown0 (0.0%)
Required4 (6.3%)
Privileges Required
Low4 (6.3%)
High1 (1.6%)
None58 (92.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (63 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by OpenJS Foundation as a CNA.

Media Mentions

Media articles that mention a CVE ID published by OpenJS Foundation as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs