Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Nestjs

First CVE: Mar 6, 2023Active for: 3 yearsTotal CVEs: 8

NestJS is a widely adopted Node.js framework for building server-side applications, and despite a narrow product footprint, occupies a prominent position in modern backend development infrastructure. Vulnerabilities affecting the vendor skew toward serious outcomes and frequently acquire public exploit code; the exposure recurs across the core framework and its development tooling through a pattern of control-flow irregularities, code injection vectors, and CSRF weaknesses that reflect the framework's middleware-oriented architecture and code-generation facilities. Defenders should monitor this vendor's releases closely given the framework's broad deployment in business-critical services and the inherent reach of framework-level flaws; current severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
1.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 76% of tracked vendors
7.2
Avg CVSS Score
Higher Avg CVSS Score than 54% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Nestjs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 6, 2023
3 years ago
Most Recent CVE
Apr 21, 2026
94 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-54782HIGH
Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the
Aug 2, 20258.869NOYES
CVE-2026-2293CRITICAL
A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue a
Feb 27, 20269.839NONO
CVE-2026-40879HIGH
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker sends many small, valid JSON messages in one TCP frame, handleData()
Apr 21, 20267.525NONO
CVE-2026-33011HIGH
Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS application using @nestjs/platform-fastify GET middleware can be
Mar 20, 20267.525NONO
CVE-2025-69211HIGH
Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is vulnera
Dec 29, 20257.424NONO
CVE-2026-35515MEDIUM
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.18, SseStream._transform() interpolates message.type and message.id directly into Server-S
Apr 7, 20266.121NONO
CVE-2023-26108MEDIUM
Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe. Exploiting this vulnerability is possible when the client canc
Mar 6, 20235.319NONO
CVE-2024-29409MEDIUM
File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.
Mar 14, 20255.517NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
38%
50%
13%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None5 (62.5%)
Unknown0 (0.0%)
Required3 (37.5%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None7 (87.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
12.5% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Nestjs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Nestjs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Nestjs's Products

View all 4 CNAs →

Top CWEs