Feathersjs maintains a focused framework and ecosystem for building real-time web and mobile applications, with vulnerability disclosures concentrating in the core Feathers framework and its Sequelize database integration. Its vulnerability profile skews strongly toward critical-severity outcomes and recurs through weakness classes including SQL injection, improper authentication, information exposure, and insufficient validation of exceptional conditions—issues characteristic of server-side application frameworks where database-query construction and access control underpin the entire request handler chain. Defenders should prioritize updates to this framework, particularly where it handles untrusted inputs or database access in production deployments; live severity and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Feathersjs over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-2422CRITICAL Due to improper input validation in the Feathers js library, it is possible to perform a SQL injection attack on the back-end database, in case the feathers-sequelize package is us | Oct 26, 2022 | 9.8 | 32 | NO | NO |
CVE-2022-29823CRITICAL Feather-Sequalize cleanQuery method uses insecure recursive logic to filter unsupported keys from the query object. This results in a Remote Code Execution (RCE) with privileges of | Oct 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-29822CRITICAL Due to improper parameter filtering in the Feathers js library, which may ultimately lead to SQL injection | Oct 26, 2022 | 9.8 | 31 | NO | NO |
CVE-2026-29793CRITICAL Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, Socket.IO clients can send arbitrary JavaScr | Mar 10, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-29792CRITICAL Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. From 5.0.0 to before 5.0.42, an unauthenticated attacker can send a crafte | Mar 10, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-27192HIGH Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, origin validation uses startsWith() for comp | Feb 21, 2026 | 8.1 | 26 | NO | NO |
CVE-2023-37899HIGH Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Feathers socket handler did not catch invalid string conversion errors lik | Jul 19, 2023 | 7.5 | 23 | NO | NO |
CVE-2026-27191MEDIUM Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. Versions 5.0.39 and below the redirect query parameter is appended to the | Feb 21, 2026 | 6.1 | 22 | NO | NO |
CVE-2026-27193MEDIUM Feathersjs is a framework for creating web APIs and real-time applications with TypeScript or JavaScript. In versions 5.0.39 and below, all HTTP request headers are stored in the s | Feb 21, 2026 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Feathersjs.
Media articles that mention a CVE ID that affects a product developed by Feathersjs — matched by CVE ID, not by vendor name.