Vulnerability Directory
If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.
Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.
Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
High
Node.js
Node.js
Denial of Service
17.x (<=17.9.1); 18.x (<18.14.1); 19.x (<19.6.1)
Sep 11, 2026
Medium
Node.js
Node.js
Improper Certificate Validation
>=12.0.0 <=12.22.12; >=14.0.0 <=14.21.3; >=16.0.0 <16.20.1; >=17.0.0 <=17.9.1; >=18.0.0 <18.16.1; >=19.0.0 <=19.9.0; >=20.0.0 <20.3.1
Sep 11, 2026
Medium
Node.js
Node.js
Improper Certificate Validation
17.x (<=17.9.0); 18.x (<=18.1.0); Node.js NES 16.x (<16.20.3)
Sep 11, 2026
High
Jackson
jackson-databind
Denial of Service
>=2.0.0 <2.18.10, >=2.19.0 <2.21.6, >=2.22.0 <2.22.2, >=3.0.0 <3.1.6, >=3.2.0 <3.2.2
Sep 11, 2026
Medium
Jackson
jackson-dataformat-toml
Denial of Service
2.13.5, 2.14.3, >=2.15.0 <2.18.10, >=2.19.0 <2.21.6, >=3.0.0 <3.1.6
Sep 11, 2026
High
Jetty
jetty-http
HTTP Request Smuggling
>=9.4.0 <9.4.64, >=10.0.0 <10.0.32, >=11.0.0 <11.0.32, >=12.0.0 <12.0.38, >=12.1.0 <12.1.12
Sep 10, 2026
High
Jetty
Eclipse Jetty
Uncontrolled Resource Consumption
>=9.4.36 <9.4.64, >=10.0.0 <10.0.32, >=11.0.0 <11.0.32, >=12.0.0 <12.0.38, >=12.1.0 <12.1.11
Sep 10, 2026
High
Jetty
Eclipse Jetty
Denial of Service
>=10.0.0 <10.0.32, >=11.0.0 <11.0.32, >=12.0.0 <12.0.38, >=12.1.0 <12.1.12
Sep 10, 2026
No results found
Please enter a valid Vulnerability ID number or Technology name.
