Nest
Vendor:
First CVE: Mar 6, 2023 · Active for 3 years
7
Total CVEs
More Total CVEs than 85% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Nest over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 6, 2023
3 years ago
Most Recent CVE
Apr 21, 2026
97 days ago
CVE Severity & Scoring
Nest7 CVEs
43%
43%
14%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None5 (71.4%)
Unknown0 (0.0%)
Required2 (28.6%)
Privileges Required
Low1 (14.3%)
High0 (0.0%)
None6 (85.7%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-2293CRITICAL A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled.
This issue a | Feb 27, 2026 | 9.8 | 39 | NO | NO |
CVE-2026-40879HIGH Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker sends many small, valid JSON messages in one TCP frame, handleData() | Apr 21, 2026 | 7.5 | 25 | NO | NO |
CVE-2026-33011HIGH Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS application using @nestjs/platform-fastify GET middleware can be | Mar 20, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-69211HIGH Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is vulnera | Dec 29, 2025 | 7.4 | 24 | NO | NO |
CVE-2026-35515MEDIUM Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.18, SseStream._transform() interpolates message.type and message.id directly into Server-S | Apr 7, 2026 | 6.1 | 21 | NO | NO |
CVE-2023-26108MEDIUM Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe. Exploiting this vulnerability is possible when the client canc | Mar 6, 2023 | 5.3 | 19 | NO | NO |
CVE-2024-29409MEDIUM File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header. | Mar 14, 2025 | 5.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Nest
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 11.1.13 | 1 | 9.8 | 0.7% | 0 | 0 |
| 10.3.2 | 1 | 5.5 | 0.3% | 0 | 0 |