Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Node.js

First CVE: Aug 13, 2012Active for: 14 yearsTotal CVEs: 239
70.5
VTI Score
TOP TARGET

Node.js is a foundational JavaScript runtime environment embedded across a vast array of server-side applications, development tools, and production systems, conferring outsized prominence to its vulnerability profile despite a narrow product portfolio. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the runtime's core role in handling untrusted network input and managing application lifecycle resources. The exposure recurs across the Node.js runtime itself and its bundled HTTP client library Undici through weakness classes including uncontrolled resource consumption, improper input validation, and exposure of sensitive information—patterns characteristic of network-facing parsers and resource-management code paths. Defenders should treat Node.js advisories as broadly applicable within their infrastructure and prioritize runtime updates; current exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
239
Total CVEs
More Total CVEs than 100% of tracked vendors
5.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
0.4%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Node.js over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 13, 2012
13 years ago
Most Recent CVE
Jun 26, 2026
28 days ago

Self-Reporting Analysis

Of all the CVEs published by Node.js as a CNA, 100.0% affect products that Node.js develops as a vendor.

100.0%
Self-reported: 18 (100.0%)
Third-party: 0 (0.0%)

Of all the CVEs published that affect products developed by Node.js, 7.5% are self-published by Node.js as a CNA.

92.5%
Self-published: 18 (7.5%)
Other CNAs: 221 (92.5%)

Products(3 total)

Top CVEs

Signals from CVEs in this vendor scope (239 CVEs).

239 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-44487HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
CVE-2014-0224HIGH
OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to
Jun 5, 20147.483NOYES
CVE-2016-2107MEDIUM
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obta
May 5, 20165.979NOYES
CVE-2016-2183HIGH
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which mak
Sep 1, 20167.577NONO
CVE-2022-3786HIGH
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification
Nov 1, 20227.576NONO
CVE-2022-3602HIGH
A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification
Nov 1, 20227.575NONO
CVE-2024-27983HIGH
An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave so
Apr 9, 20248.274NONO
CVE-2022-32214MEDIUM
The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Sm
Jul 14, 20226.567NONO
CVE-2021-22883HIGH
Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This
Mar 3, 20217.567NONO
CVE-2019-9515HIGH
Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RF
Aug 13, 20197.566NONO
View all 239 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products239 CVEs
33%
52%
8%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local22 (9.2%)
Network209 (87.4%)
Unknown8 (3.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low182 (76.2%)
High49 (20.5%)
Unknown8 (3.3%)
User Interaction
None202 (84.5%)
Unknown8 (3.3%)
Required29 (12.1%)
Privileges Required
Low30 (12.6%)
High5 (2.1%)
None196 (82.0%)
Unknown8 (3.3%)

Exploit Exposure

Signals from CVEs in this vendor scope (239 CVEs).

CISA KEV
1 CVE
0.4% of CVEs· 99th percentile
Metasploit
2 CVEs
0.8% of CVEs· 97th percentile
Nuclei
2 CVEs
0.8% of CVEs· 95th percentile
ExploitDB
3 CVEs
1.3% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Node.js.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Node.js — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Node.js's Products

View all 10 CNAs →

Top CWEs