Node Formidable maintains a form-parsing middleware library for Node.js applications, a narrowly scoped but commonly embedded component in web frameworks and file-upload handlers. The vendor's modest vulnerability surface centers on its core formidable product, with disclosed issues reflecting the input-handling and data-processing demands inherent to multipart form parsing. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Node Formidable over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
Formidable (aka node-formidable) 2.1.0 through 3.x before 3.5.3 relies on hexoid to prevent guessing of filenames for untrusted executable content; however, hexoid is documented as | Apr 26, 2025 | 3.1 | 14 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Node Formidable.
Media articles that mention a CVE ID that affects a product developed by Node Formidable — matched by CVE ID, not by vendor name.