
Report a CVE to HeroDevs
Committed to Security and Confidentiality
At HeroDevs, safeguarding the security of open-source software and its ecosystem is our priority. As a CVE Numbering Authority (CNA), we ensure your vulnerability reports are handled with utmost confidentiality and professionalism.
Report a Vulnerability
When you report a CVE, you can trust that:
- Your submission is reviewed promptly and securely by our team of security experts.
- Details of the vulnerability will not be disclosed until appropriate patches are developed and coordinated with the necessary stakeholders.
- Your role as the reporter will be respected, with attribution provided as per your preference.
Every vulnerability we address strengthens the open-source ecosystem and ensures the continued security of end-of-life software. At HeroDevs, we actively track, assess, and address vulnerabilities to safeguard the security of open source software and protect the businesses that rely on it.
Early Detection and CVE Remediation
187 Security Issues Fixed
(and always looking for more)
Below is a snapshot of the most recent 10 of 75 vulnerabilities in our database, demonstrating our commitment to transparency and proactive security.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Node.js
Node.js
Improper Certificate Validation
<=26.5.0; <=24.18.0; <=22.23.1 (active lines); and the End-of-Life Node.js 12.x, 14.x, 16.x, 18.x, and 20.x lines (all versions, addressed via Node.js NES)
Sep 12, 2026
Medium
Node.js
Node.js
No items found.
Node.js 22.x <=22.22.3; 24.x <=24.16.0; 26.x <=26.3.0
Sep 11, 2026
Low
Node.js
Node.js
No items found.
<=22.22.3; <=24.16.0; <=26.3.0 (per upstream advisory/NVD/CNA scope; the Permission Model was introduced in Node.js 20 and remains present in the also-affected, now-EOL Node.js 20.x line, which upstream advisory does not separately name since Node.js no longer supports that line)
Sep 11, 2026
Medium
Node.js
Node.js
No items found.
<=22.22.3; <=24.16.0; <=26.3.0 (per upstream advisory/NVD/CNA scope; HeroDevs NES additionally covers the Node.js 12, 14, 16, 18, and 20 End-of-Life lines as deliberate EOL security coverage)
Sep 11, 2026
Low
Node.js
Node.js
Incorrectly Configured Access Control
>=22.0.0 <22.23.0; >=24.0.0 <24.17.0; >=26.0.0 <26.3.1
Sep 11, 2026
High
Node.js
Node.js
Denial of Service
>=8.0.0 <19.0.0; >=20.0.0 <20.20.0; >=22.0.0 <22.22.0; >=24.0.0 <24.13.0; >=25.0.0 <25.3.0
Sep 11, 2026
Low
Node.js
Node.js
Information Exposure
>=16.15.0 <16.20.3; >=18.0.0 <18.18.2; >=19.0.0 <20.8.1
Sep 11, 2026
High
Node.js
Node.js
No items found.
20.x ≤ 20.19.6; 22.x ≤ 22.21.1; 24.x ≤ 24.12.0; 25.x ≤ 25.2.1; 4.x–18.x (EOL, all versions)
Sep 11, 2026
For more details on CVEs found in end-of-life software, visit our vulnerability directory.