Node Modules encompasses a collection of compression-related packages deployed across Node.js development environments, representing a narrow but actively maintained segment of the JavaScript ecosystem. The observed vulnerability surface clusters around compression libraries and their handling of data streams, reflecting the encoding and format-parsing complexity inherent to this class of tools. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Node Modules over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40931HIGH Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical string validation within the isPathW | Apr 21, 2026 | 7.8 | 28 | NO | NO |
CVE-2026-24884HIGH Compressing is a compressing and uncompressing lib for node. In version 2.0.0 and 1.10.3 and prior, Compressing extracts TAR archives while restoring symbolic links without validat | Feb 4, 2026 | 7.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Node Modules.
Media articles that mention a CVE ID that affects a product developed by Node Modules — matched by CVE ID, not by vendor name.