Vulnerability Directory

If you’re currently using these frameworks in your application’s tech stack, your application could be vulnerable.

Secure drop-in replacements for open source software from HeroDevs helps you stay secure, compliant, and compatible while you migrate.

Switch to Never-Ending Support (NES) from HeroDevs to immediately mitigate these vulnerabilities.

Codey gradient
Filtering by:
Severity
=
Text for Severity
Close icon
Clear Filters
Severity
ID
Technology
Libraries Affected
Category
Version(s) Affected
Published Date
Medium
Node.js
Node.js
Improper Certificate Validation
<=26.5.0; <=24.18.0; <=22.23.1 (active lines); and the End-of-Life Node.js 12.x, 14.x, 16.x, 18.x, and 20.x lines (all versions, addressed via Node.js NES)
Sep 12, 2026
Medium
Node.js
Node.js
No items found.
<=22.22.3; <=24.16.0
Sep 11, 2026
Medium
Node.js
Node.js
No items found.
Node.js 22.x <=22.22.3; 24.x <=24.16.0; 26.x <=26.3.0
Sep 11, 2026
Medium
Node.js
Node.js
Denial of Service
<=22.22.3; <=24.16.0; <=26.3.0
Sep 11, 2026
Low
Node.js
Node.js
No items found.
<=22.22.3; <=24.16.0; <=26.3.0 (per upstream advisory/NVD/CNA scope; the Permission Model was introduced in Node.js 20 and remains present in the also-affected, now-EOL Node.js 20.x line, which upstream advisory does not separately name since Node.js no longer supports that line)
Sep 11, 2026
Medium
Node.js
Node.js
No items found.
<=22.22.3; <=24.16.0; <=26.3.0 (per upstream advisory/NVD/CNA scope; HeroDevs NES additionally covers the Node.js 12, 14, 16, 18, and 20 End-of-Life lines as deliberate EOL security coverage)
Sep 11, 2026
Low
Node.js
Node.js
Incorrectly Configured Access Control
>=22.0.0 <22.23.0; >=24.0.0 <24.17.0; >=26.0.0 <26.3.1
Sep 11, 2026
High
Node.js
Node.js
Denial of Service
>=8.0.0 <19.0.0; >=20.0.0 <20.20.0; >=22.0.0 <22.22.0; >=24.0.0 <24.13.0; >=25.0.0 <25.3.0
Sep 11, 2026
Low
Node.js
Node.js
Information Exposure
>=16.15.0 <16.20.3; >=18.0.0 <18.18.2; >=19.0.0 <20.8.1
Sep 11, 2026
High
Node.js
Node.js
No items found.
20.x ≤ 20.19.6; 22.x ≤ 22.21.1; 24.x ≤ 24.12.0; 25.x ≤ 25.2.1; 4.x–18.x (EOL, all versions)
Sep 11, 2026
High
Node.js
Node.js
Denial of Service
Per the Node.js security blog (March 24, 2026 release, SNICallback gap): >=20.0.0 <20.20.2; >=22.0.0 <22.22.2; >=24.0.0 <24.14.1; >=25.0.0 <25.8.2. Per NVD's own record (published January 20, 2026, pskCallback/ALPNCallback only): >=4.0.0 <20.20.0; >=22.0.0 <22.22.0; >=24.0.0 <24.13.0; >=25.0.0 <25.3.0.
Sep 11, 2026
High
Node.js
Node.js
No items found.
>=12.0.0 <=12.22.12; >=14.0.0 <=14.21.3; >=16.0.0 <16.20.1; >=18.0.0 <18.16.1; >=20.0.0 <20.3.1
Sep 11, 2026
Medium
Node.js
Node.js
No items found.
>=12.0.0 <=12.22.12; >=14.0.0 <=14.21.3; >=16.0.0 <16.20.1; >=18.0.0 <18.16.1; >=20.0.0 <20.3.1
Sep 11, 2026
Medium
Node.js
Node.js
No items found.
>=12.0.0 <=12.22.12; >=14.0.0 <=14.21.3; >=16.0.0 <16.20.1; >=18.0.0 <18.16.1; >=20.0.0 <20.3.1
Sep 11, 2026
Low
Node.js
Node.js
No items found.
>=12.0.0 <=12.22.12; >=14.0.0 <=14.21.3; >=16.0.0 <16.20.1; >=18.0.0 <18.16.1; >=20.0.0 <20.3.1
Sep 11, 2026
Exclamation icon
No results found

Please enter a valid Vulnerability ID number or Technology name.

Sign up for the latest vulnerability alerts
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.