NestJS is a widely adopted Node.js framework for building server-side applications, and despite a narrow product footprint, occupies a prominent position in modern backend development infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure recurs across the core framework and its development tooling through a pattern of control-flow irregularities, code injection vectors, and CSRF weaknesses that reflect the framework's middleware-oriented architecture and code-generation facilities. Defenders should monitor this vendor's releases closely given the framework's broad deployment in business-critical services and the inherent reach of framework-level flaws; current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nestjs over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-54782HIGH Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the | Aug 2, 2025 | 8.8 | 69 | NO | YES |
CVE-2026-2293CRITICAL A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled.
This issue a | Feb 27, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-40879HIGH Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker sends many small, valid JSON messages in one TCP frame, handleData() | Apr 21, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-33011HIGH Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS application using @nestjs/platform-fastify GET middleware can be | Mar 20, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-69211HIGH Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is vulnera | Dec 29, 2025 | 7.4 | 24 | NO | NO |
CVE-2026-35515MEDIUM Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.18, SseStream._transform() interpolates message.type and message.id directly into Server-S | Apr 7, 2026 | 6.1 | 21 | NO | NO |
CVE-2023-26108MEDIUM Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe. Exploiting this vulnerability is possible when the client canc | Mar 6, 2023 | 5.3 | 19 | NO | NO |
CVE-2024-29409MEDIUM File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header. | Mar 14, 2025 | 5.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nestjs.
Media articles that mention a CVE ID that affects a product developed by Nestjs — matched by CVE ID, not by vendor name.