Node.js is a foundational JavaScript runtime environment embedded across a vast array of server-side applications, development tools, and production systems, conferring outsized prominence to its vulnerability profile despite a narrow product portfolio. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the runtime's core role in handling untrusted network input and managing application lifecycle resources. The exposure recurs across the Node.js runtime itself and its bundled HTTP client library Undici through weakness classes including uncontrolled resource consumption, improper input validation, and exposure of sensitive information—patterns characteristic of network-facing parsers and resource-management code paths. Defenders should treat Node.js advisories as broadly applicable within their infrastructure and prioritize runtime updates; current exploitation activity and severity counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Node.js over time
Of all the CVEs published by Node.js as a CNA, 100.0% affect products that Node.js develops as a vendor.
Of all the CVEs published that affect products developed by Node.js, 7.5% are self-published by Node.js as a CNA.
Signals from CVEs in this vendor scope (239 CVEs).
239 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2014-0224HIGH OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to | Jun 5, 2014 | 7.4 | 83 | NO | YES |
CVE-2016-2107MEDIUM The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a certain padding check, which allows remote attackers to obta | May 5, 2016 | 5.9 | 79 | NO | YES |
CVE-2016-2183HIGH The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which mak | Sep 1, 2016 | 7.5 | 77 | NO | NO |
CVE-2022-3786HIGH A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification | Nov 1, 2022 | 7.5 | 76 | NO | NO |
CVE-2022-3602HIGH A buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. Note that this occurs after certificate chain signature verification | Nov 1, 2022 | 7.5 | 75 | NO | NO |
CVE-2024-27983HIGH An attacker can make the Node.js HTTP/2 server completely unavailable by sending a small amount of HTTP/2 frames packets with a few HTTP/2 frames inside. It is possible to leave so | Apr 9, 2024 | 8.2 | 74 | NO | NO |
CVE-2022-32214MEDIUM The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Sm | Jul 14, 2022 | 6.5 | 67 | NO | NO |
CVE-2021-22883HIGH Node.js before 10.24.0, 12.21.0, 14.16.0, and 15.10.0 is vulnerable to a denial of service attack when too many connection attempts with an 'unknownProtocol' are established. This | Mar 3, 2021 | 7.5 | 67 | NO | NO |
CVE-2019-9515HIGH Some HTTP/2 implementations are vulnerable to a settings flood, potentially leading to a denial of service. The attacker sends a stream of SETTINGS frames to the peer. Since the RF | Aug 13, 2019 | 7.5 | 66 | NO | NO |
Signals from CVEs in this vendor scope (239 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Node.js.
Media articles that mention a CVE ID that affects a product developed by Node.js — matched by CVE ID, not by vendor name.