Vulnerability Directory

If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.

Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.

Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.

Codey gradient
Filtering by:
Severity
=
Text for Severity
Close icon
Clear Filters
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Node.js
Node.js
No items found.
<=22.22.3; <=24.16.0; <=26.3.0 (per upstream advisory/NVD/CNA scope; HeroDevs NES additionally covers the Node.js 12, 14, 16, 18, and 20 End-of-Life lines as deliberate EOL security coverage)
Sep 11, 2026
Low
Node.js
Node.js
Incorrectly Configured Access Control
>=22.0.0 <22.23.0; >=24.0.0 <24.17.0; >=26.0.0 <26.3.1
Sep 11, 2026
High
Node.js
Node.js
Denial of Service
>=8.0.0 <19.0.0; >=20.0.0 <20.20.0; >=22.0.0 <22.22.0; >=24.0.0 <24.13.0; >=25.0.0 <25.3.0
Sep 11, 2026
Low
Node.js
Node.js
Information Exposure
>=16.15.0 <16.20.3; >=18.0.0 <18.18.2; >=19.0.0 <20.8.1
Sep 11, 2026
High
Node.js
Node.js
Information Exposure
20.x ≤ 20.19.6; 22.x ≤ 22.21.1; 24.x ≤ 24.12.0; 25.x ≤ 25.2.1; 4.x–18.x (EOL, all versions)
Sep 11, 2026
High
Node.js
Node.js
Denial of Service
Per the Node.js security blog (March 24, 2026 release, SNICallback gap): >=20.0.0 <20.20.2; >=22.0.0 <22.22.2; >=24.0.0 <24.14.1; >=25.0.0 <25.8.2. Per NVD's own record (published January 20, 2026, pskCallback/ALPNCallback only): >=4.0.0 <20.20.0; >=22.0.0 <22.22.0; >=24.0.0 <24.13.0; >=25.0.0 <25.3.0.
Sep 11, 2026
High
Node.js
Node.js
Denial of Service
>=12.0.0 <=12.22.12; >=14.0.0 <=14.21.3; >=16.0.0 <16.20.1; >=18.0.0 <18.16.1; >=20.0.0 <20.3.1
Sep 11, 2026
Medium
Node.js
Node.js
Cryptographic Weakness
>=12.0.0 <=12.22.12; >=14.0.0 <=14.21.3; >=16.0.0 <16.20.1; >=18.0.0 <18.16.1; >=20.0.0 <20.3.1
Sep 11, 2026
Medium
Node.js
Node.js
Buffer Over-read
>=12.0.0 <=12.22.12; >=14.0.0 <=14.21.3; >=16.0.0 <16.20.1; >=18.0.0 <18.16.1; >=20.0.0 <20.3.1
Sep 11, 2026
Low
Node.js
Node.js
Cryptographic Weakness
>=12.0.0 <=12.22.12; >=14.0.0 <=14.21.3; >=16.0.0 <16.20.1; >=18.0.0 <18.16.1; >=20.0.0 <20.3.1
Sep 11, 2026
High
Node.js
Node.js
Cryptographic Weakness
>=12.0.0 <=12.22.12; >=14.0.0 <=14.21.3; >=16.0.0 <=16.20.2; >=17.0.0 <=17.9.1; >=18.0.0 <18.19.0; >=19.0.0 <=19.9.0; >=20.0.0 <20.10.0
Sep 11, 2026
Medium
Node.js
Node.js
Improper Certificate Validation
>=12.0.0 <=12.22.12; >=14.0.0 <=14.21.3; >=16.0.0 <16.20.1; >=17.0.0 <=17.9.1; >=18.0.0 <18.16.1; >=19.0.0 <=19.9.0; >=20.0.0 <20.3.1
Sep 11, 2026
High
Node.js
Node.js
Stack-based Buffer Overflow
>=18.0.0 <18.12.1; >=19.0.0 <19.0.1
Sep 11, 2026
High
Node.js
Node.js
Stack-based Buffer Overflow
>=18.0.0 <18.12.1; >=19.0.0 <19.0.1
Sep 11, 2026
High
Node.js
Node.js
Cryptographic Weakness
>=17.0.0 <=17.9.1; >=18.0.0 <18.12.1; >=19.0.0 <19.0.1
Sep 11, 2026
Exclamation icon
No results found

Please enter a valid Vulnerability ID number or Technology name.

Sign up for the latest vulnerability alerts
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.