Esm.Sh
Vendor:
First CVE: Nov 19, 2025 · Active for under a year
5
Total CVEs
More Total CVEs than 79% of tracked products
2.5
Avg CVEs / Year
Higher CVE frequency than 77% of tracked products
8.4
Avg CVSS
Higher Avg CVSS than 76% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Esm.Sh over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 19, 2025
8 months ago
Most Recent CVE
Feb 25, 2026
152 days ago
CVE Severity & Scoring
Esm.Sh5 CVEs
60%
40%
All CVEs352,785 CVEs
45%
40%
11%
HighCritical
Attack Vector
Local0 (0.0%)
Network5 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low5 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None4 (80.0%)
Unknown0 (0.0%)
Required1 (20.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None5 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-65026CRITICAL esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, The esm.sh CDN service contains a Template Literal Injection vulnerability (CWE- | Nov 19, 2025 | 9.6 | 30 | NO | NO |
CVE-2025-65025CRITICAL esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, the esm.sh CDN service is vulnerable to path traversal during NPM package tarbal | Nov 19, 2025 | 9.8 | 27 | NO | NO |
CVE-2026-27730HIGH esm.sh is a no-build content delivery network (CDN) for web development. Versions up to and including 137 have an SSRF vulnerability (CWE-918) in esm.sh’s `/http(s)` fetch route. T | Feb 25, 2026 | 7.5 | 26 | NO | NO |
CVE-2025-50180HIGH esm.sh is a no-build content delivery network (CDN) for web development. In version 136, esm.sh is vulnerable to a full-response SSRF, allowing an attacker to retrieve information | Feb 25, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-23644HIGH esm.sh is a no-build content delivery network (CDN) for web development. Prior to Go pseeudoversion 0.0.0-20260116051925-c62ab83c589e, the software has a path traversal vulnerabili | Jan 18, 2026 | 7.5 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (5 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (5 CVEs).
Media Mentions
Signals from CVEs in this product scope (5 CVEs).
Top CNAs Publishing CVEs For Esm.Sh
Top CWEs
Versions
No cataloged versions.