CVE Tools

Nodejs

194 CVEs tracked since 2013. Since Jul 2013, 1 of them reached CISA KEV.

Nodejs CVEs per month

Jul 2013 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Nodejs CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2013-0710
2013-08null or fewer
2013-09null or fewer
2013-1010
2013-11null or fewer
2013-12null or fewer
2014-01null or fewer
2014-02null or fewer
2014-0310
2014-04null or fewer
2014-05null or fewer
2014-0610
2014-07null or fewer
2014-08null or fewer
2014-09null or fewer
2014-10null or fewer
2014-11null or fewer
2014-12null or fewer
2015-01null or fewer
2015-02null or fewer
2015-03null or fewer
2015-04null or fewer
2015-0510
2015-06null or fewer
2015-0710
2015-08null or fewer
2015-09null or fewer
2015-10null or fewer
2015-11null or fewer
2015-1230
2016-0110
2016-02null or fewer
2016-0320
2016-0420
2016-0530
2016-0610
2016-0710
2016-08null or fewer
2016-0960
2016-1030
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-0570
2017-06null or fewer
2017-0720
2017-08null or fewer
2017-0920
2017-1030
2017-11null or fewer
2017-1230
2018-01null or fewer
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-0660
2018-07null or fewer
2018-0820
2018-09null or fewer
2018-1020
2018-11null or fewer
2018-12null or fewer
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-05null or fewer
2019-06null or fewer
2019-07null or fewer
2019-0880
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-0240
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-0620
2020-07null or fewer
2020-08null or fewer
2020-0930
2020-10null or fewer
2020-11null or fewer
2020-12null or fewer
2021-0120
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-05null or fewer
2021-06null or fewer
2021-07null or fewer
2021-0830
2021-09null or fewer
2021-10null or fewer
2021-1130
2021-12null or fewer
2022-01null or fewer
2022-0240
2022-03null or fewer
2022-04null or fewer
2022-05null or fewer
2022-06null or fewer
2022-0790
2022-08null or fewer
2022-09null or fewer
2022-10null or fewer
2022-11null or fewer
2022-1230
2023-01null or fewer
2023-0250
2023-03null or fewer
2023-04null or fewer
2023-05null or fewer
2023-06null or fewer
2023-07null or fewer
2023-0850
2023-09null or fewer
2023-1051
2023-1140
2023-12null or fewer
2024-01null or fewer
2024-0270
2024-03null or fewer
2024-04null or fewer
2024-05null or fewer
2024-06null or fewer
2024-07null or fewer
2024-08null or fewer
2024-0980
2024-10null or fewer
2024-11null or fewer
2024-12null or fewer
2025-0150
2025-02null or fewer
2025-03null or fewer
2025-04null or fewer
2025-0540
2025-06null or fewer
2025-07null or fewer
2025-08null or fewer
2025-09null or fewer
2025-10null or fewer
2025-11null or fewer
2025-12null or fewer
2026-0190
2026-02null or fewer
2026-03140
2026-04null or fewer
2026-05null or fewer
2026-06200
2026-07null or fewer
2026-08null or fewer
2026-09120

Products

The products that kept showing up in Nodejs's monthly top three, with their CVEs summed over those months.

  1. Node.js13040 months
  2. Node9020 months
  3. Undici3610 months
  4. Nodejs11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Nodejs.

  1. CVE-2026-18149undici vulnerable to Denial of Service via orphaned RetryHandler response body5.9
  2. CVE-2026-18540undici vulnerable to downstream response splitting via retry interceptor3.7
  3. CVE-2026-19534undici vulnerable to Denial of Service via unrequested WebSocket subprotocol7.5
  4. CVE-2026-84890undici vulnerable to Denial of Service via unbounded decompression of compressed responses5.9
  5. CVE-2026-84933undici vulnerable to cross-user cookie disclosure via Set-Cookie caching in shared caches6.5
  6. CVE-2026-84947undici vulnerable to response truncation via oversized chunked responses in the dump interceptor3.7
  7. CVE-2026-84961undici vulnerable to TLS certificate validation bypass via dropped connect options in BalancedPool7.4
  8. CVE-2026-85008undici vulnerable to caching and replay of unsafe HTTP method responses3.7
  9. CVE-2026-85152undici vulnerable to cross-origin cache poisoning via missing origin isolation in interceptors7.4
  10. CVE-2026-85014undici vulnerable to Denial of Service via WebSocketStream unclean close5.9
  11. CVE-2026-85024undici vulnerable to Denial of Service via unhandled error in WebSocket permessage-deflate decompression5.9
  12. CVE-2026-48932A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the or...3.7
  13. CVE-2026-56848A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerab...7.5
  14. CVE-2026-56846A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.7.5
  15. CVE-2026-58044A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible `IncomingMessage` headers while piping the or...3.7

The record

Peak rank
#31 in Sep 2016
Busiest month shown
Jun 2026, 20 CVEs
Months with a KEV entry
1 since Jul 2013
Monthly snapshots
45 since 2013
Nodejs's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store