Request Pricing
Every unpatched CVE is a risk. Fix them all now.
High
Node.js
Node.js
Uncontrolled Resource Consumption
>=8.4.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <=16.20.2 >=17.0.0 <=17.9.1 >=18.0.0 <18.18.2 >=19.0.0 <=19.9.0 >=20.0.0 <20.5.0
October 8, 2026
Medium
Node.js
Node.js
Privilege Escalation
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.19.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.14.1 >=19.0.0 <19.6.1
October 8, 2026
Medium
Node.js
Node.js
Denial of Service
>=17.0.0 <=17.9.1 >=18.0.0 <18.19.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.11.1 >=21.0.0 <21.6.2
October 8, 2026
Medium
Node.js
Node.js
Unchecked Input for Loop Condition
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <=16.20.2 >=17.0.0 <=17.9.1 >=18.0.0 <18.19.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.11.1 >=21.0.0 <21.6.2
October 8, 2026
Medium
Node.js
Node.js
Unchecked Input for Loop Condition
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.20.2 >=17.0.0 <=17.9.1 >=18.0.0 <18.17.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.5.1
October 8, 2026
Medium
Node.js
Node.js
Cryptographic Weakness
>=17.0.0 <=17.9.1 >=18.0.0 <18.17.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.5.1
October 8, 2026
Medium
Node.js
Node.js
Inefficient Algorithmic Complexity
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.20.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.16.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.3.1
October 8, 2026
Medium
Node.js
Node.js
Buffer Over-read
>=17.0.0 <=17.9.1 >=18.0.0 <18.16.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.3.1
October 8, 2026
High
Node.js
Node.js
Inefficient Algorithmic Complexity
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.20.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.16.1 >=19.0.0 <=19.9.0 >=20.0.0 <20.3.1
October 8, 2026
High
Node.js
Node.js
Access of Resource Using Incompatible Type ('Type Confusion')
>=4.0.0 <=4.9.1 >=5.0.0 <=5.12.0 >=6.0.0 <=6.17.1 >=7.0.0 <=7.10.1 >=8.0.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.16.0 <=10.24.1 >=11.9.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <16.19.1 >=17.0.0 <=17.9.1 >=18.0.0 <18.14.1 >=19.0.0 <19.6.1
October 8, 2026
Ensuring Full Compliance and Security
Never-Ending Support ensures your end-of-life open-source software stays fully compliant with industry standards like HIPAA, PCI, SOC2 and FedRAMP. With ongoing security updates and a commitment to audit readiness, you can rest easy knowing your systems remain compliant, secure, and ready for any inspection.
Trusted by 1,000+ Companies, 8,000+ Developers
“From the very first point of contact, working with HeroDevs has been an exceptional experience. The option to install EOL Support, rather than undertaking a full internal migration, has saved us significant time, money, and frustrations.”
UI/UX Engineering Manager
Frequently Asked Questions
Get answers to some of our most commonly asked questions.
Of course, if you can't find the answer you're looking for, feel free to contact us.
How does intellectual property for NES libraries work?
Do I pay extra for development, staging, etc. environments?
What makes onboarding so easy?
How hard is it to get this through our InfoSec and Legal procurement process?
Do you offer discounts for nonprofits, open source companies, or educational institutions?
Do you have multi-year license options?
How are licenses tracked? Do you install a license server?
What happens if team members leave or join after we’ve purchased licenses?
What does a license cover?