The OpenJS Foundation maintains a portfolio of widely adopted Node.js frameworks and middleware components such as Express, Fastify, and body-parser that underpin numerous web applications and APIs. Vulnerabilities affecting these products center on web application input-handling and server-side code-generation issues, notably cross-site scripting, OS command injection, and prototype pollution, reflecting the exposure surface of JavaScript runtime environments. Current severity, exploitation activity, and product coverage are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openjsf over time
Signals from CVEs in this vendor scope (19 CVEs).
19 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-25244CRITICAL WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnera | May 18, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-13676HIGH fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the | Jun 29, 2026 | 7.5 | 37 | NO | NO |
CVE-2026-6322HIGH fast-uri normalize() decoded percent-encoded authority delimiters inside the host component and then re-emitted them as raw delimiters during serialization. A host that combined an | May 5, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-6321HIGH fast-uri decoded percent-encoded path separators and dot segments before applying dot-segment removal in its normalize() and equal() functions. Encoded path data was treated like r | May 4, 2026 | 7.5 | 36 | NO | NO |
CVE-2026-10796HIGH nvm (Node Version Manager) through 0.40.4 executes arbitrary commands from version strings supplied by the configured Node.js/io.js mirror. Commands such as `nvm install` read the | Jun 4, 2026 | 7.5 | 33 | NO | NO |
CVE-2022-24999HIGH qs before 6.10.3, as used in Express before 4.17.3 and other products, allows attackers to cause a Node process hang for an Express application because an __ proto__ key can be use | Nov 26, 2022 | 7.5 | 32 | NO | NO |
CVE-2026-12590MEDIUM Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 (2.x line), when the parser is configured with an invalid limit option value such as an unparseable string or N | Jul 9, 2026 | 5.9 | 29 | NO | NO |
CVE-2025-57349HIGH The messageformat package, an implementation of the Unicode MessageFormat 2 specification for JavaScript, is vulnerable to prototype pollution due to improper handling of message k | Sep 24, 2025 | 7.5 | 25 | NO | NO |
CVE-2024-45590HIGH body-parser is Node.js body parsing middleware. body-parser <1.20.3 is vulnerable to denial of service when url encoding is enabled. A malicious actor using a specially crafted pay | Sep 10, 2024 | 7.5 | 25 | NO | NO |
CVE-2025-50537MEDIUM Stack overflow vulnerability in eslint before 9.26.0 when serializing objects with circular references in eslint/lib/shared/serialization.js. The exploit is triggered via the RuleT | Jan 26, 2026 | 5.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (19 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openjsf.
Media articles that mention a CVE ID that affects a product developed by Openjsf — matched by CVE ID, not by vendor name.