{"schema_version":1,"title":"Nodejs Node.js vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 14 vulnerabilities in Nodejs Node.js: 0 in the last 7 days and 2 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-58039, was published on 31 July 2026.","url":"https://junglewise.ai/threats/technologies/node-js","json_url":"https://junglewise.ai/threats/technologies/node-js.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/node-js","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":5,"all_time":14,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":2,"last_365_days":5},"latest":[{"cve":"CVE-2026-58039","cvss":3.3,"slug":"cve-2026-58039-node-js-permission-model-bypass-in-process-report","title":"Node.js Permission Model bypass in process.report","severity":"low","exploited":false,"published_at":"2026-07-31T01:16:31.53+00:00","url":"https://junglewise.ai/threats/cve-2026-58039-node-js-permission-model-bypass-in-process-report"},{"cve":"CVE-2026-58043","cvss":7.5,"slug":"cve-2026-58043-node-js-permission-model-filesystem-access-bypass","title":"Node.js Permission Model filesystem access bypass","severity":"high","exploited":false,"published_at":"2026-07-30T06:25:55.31+00:00","url":"https://junglewise.ai/threats/cve-2026-58043-node-js-permission-model-filesystem-access-bypass"},{"cve":"CVE-2026-21710","cvss":7.5,"epss":0.1307,"slug":"cve-2026-21710-node-js-denial-of-service-via-proto-header-in-req-headersdistinct","title":"Node.js denial of service via __proto__ header in req.headersDistinct","severity":"high","exploited":false,"published_at":"2026-03-30T20:16:18.21+00:00","url":"https://junglewise.ai/threats/cve-2026-21710-node-js-denial-of-service-via-proto-header-in-req-headersdistinct"},{"cve":"CVE-2025-55131","cvss":7.1,"epss":0.0098,"slug":"cve-2025-55131-node-js-uninitialized-memory-exposure-in-vm-module-buffer","title":"Node.js uninitialized memory exposure in vm module buffer allocation","severity":"high","exploited":false,"published_at":"2026-01-20T21:16:03.32+00:00","url":"https://junglewise.ai/threats/cve-2025-55131-node-js-uninitialized-memory-exposure-in-vm-module-buffer"},{"cve":"CVE-2025-55130","cvss":9.1,"epss":0.0049,"slug":"cve-2025-55130-node-js-permission-model-bypass-via-crafted-symlinks","title":"Node.js permission model bypass via crafted symlinks","severity":"critical","exploited":false,"published_at":"2026-01-20T21:16:03.177+00:00","url":"https://junglewise.ai/threats/cve-2025-55130-node-js-permission-model-bypass-via-crafted-symlinks"},{"cve":"CVE-2023-30589","cvss":3.1,"epss":0.0391,"slug":"cve-2023-30589-llhttp-http-request-smuggling-via-improper-crlf-delimiters","title":"llhttp HTTP request smuggling via improper CRLF delimiters","severity":"low","exploited":false,"published_at":"2023-07-01T00:30:46+00:00","url":"https://junglewise.ai/threats/cve-2023-30589-llhttp-http-request-smuggling-via-improper-crlf-delimiters"},{"cve":"CVE-2022-32213","cvss":3.1,"epss":0.4408,"slug":"cve-2022-32213-llhttp-http-request-smuggling-via-flawed-transfer-encoding","title":"llhttp HTTP request smuggling via flawed Transfer-Encoding parsing","severity":"low","exploited":false,"published_at":"2022-07-15T00:00:18+00:00","url":"https://junglewise.ai/threats/cve-2022-32213-llhttp-http-request-smuggling-via-flawed-transfer-encoding"},{"cve":"CVE-2015-8860","cvss":7.5,"epss":0.0491,"slug":"cve-2015-8860-node-js-tar-arbitrary-file-write-via-symlink-attack","title":"Node.js tar arbitrary file write via symlink attack","severity":"high","exploited":false,"published_at":"2017-01-23T21:59:00.69+00:00","url":"https://junglewise.ai/threats/cve-2015-8860-node-js-tar-arbitrary-file-write-via-symlink-attack"},{"cve":"CVE-2015-8855","cvss":7.5,"epss":0.0649,"slug":"cve-2015-8855-node-js-semver-regular-expression-denial-of-service","title":"Node.js semver Regular Expression Denial of Service","severity":"high","exploited":false,"published_at":"2017-01-23T21:59:00.503+00:00","url":"https://junglewise.ai/threats/cve-2015-8855-node-js-semver-regular-expression-denial-of-service"},{"cve":"CVE-2014-9772","cvss":6.1,"epss":0.0264,"slug":"cve-2014-9772-node-js-validator-xss-filter-bypass-via-hex-encoding","title":"Node.js validator XSS filter bypass via hex encoding","severity":"medium","exploited":false,"published_at":"2017-01-23T21:59:00.33+00:00","url":"https://junglewise.ai/threats/cve-2014-9772-node-js-validator-xss-filter-bypass-via-hex-encoding"},{"cve":"CVE-2013-7454","cvss":6.1,"epss":0.0186,"slug":"cve-2013-7454-node-js-validator-xss-filter-bypass-via-nested-forbidden-strings","title":"Node.js validator XSS filter bypass via nested forbidden strings","severity":"medium","exploited":false,"published_at":"2017-01-23T21:59:00.267+00:00","url":"https://junglewise.ai/threats/cve-2013-7454-node-js-validator-xss-filter-bypass-via-nested-forbidden-strings"},{"cve":"CVE-2013-7453","cvss":6.1,"epss":0.0186,"slug":"cve-2013-7453-node-js-validator-xss-filter-bypass-via-ui-redressing","title":"Node.js validator XSS filter bypass via UI redressing","severity":"medium","exploited":false,"published_at":"2017-01-23T21:59:00.237+00:00","url":"https://junglewise.ai/threats/cve-2013-7453-node-js-validator-xss-filter-bypass-via-ui-redressing"},{"cve":"CVE-2013-7452","cvss":6.1,"epss":0.0205,"slug":"cve-2013-7452-node-js-validator-xss-filter-bypass-via-javascript-uri","title":"Node.js validator XSS filter bypass via javascript URI","severity":"medium","exploited":false,"published_at":"2017-01-23T21:59:00.207+00:00","url":"https://junglewise.ai/threats/cve-2013-7452-node-js-validator-xss-filter-bypass-via-javascript-uri"},{"cve":"CVE-2013-7451","cvss":6.1,"epss":0.0186,"slug":"cve-2013-7451-node-js-validator-xss-filter-bypass-via-nested-tags","title":"Node.js validator XSS filter bypass via nested tags","severity":"medium","exploited":false,"published_at":"2017-01-23T21:59:00.143+00:00","url":"https://junglewise.ai/threats/cve-2013-7451-node-js-validator-xss-filter-bypass-via-nested-tags"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Nodejs Node.js","slug":"node-js","vendor":{"name":"Nodejs","slug":"nodejs","url":"https://junglewise.ai/threats/vendors/nodejs"},"aliases":[],"category":"runtime","homepage":"https://nodejs.org/","repo_url":"https://github.com/nodejs/node","description":"An open-source, cross-platform JavaScript runtime environment that executes JavaScript code outside a web browser.","url":"https://junglewise.ai/threats/technologies/node-js"},"most_severe":[{"cve":"CVE-2025-55130","cvss":9.1,"epss":0.0049,"slug":"cve-2025-55130-node-js-permission-model-bypass-via-crafted-symlinks","title":"Node.js permission model bypass via crafted symlinks","severity":"critical","exploited":false,"published_at":"2026-01-20T21:16:03.177+00:00","url":"https://junglewise.ai/threats/cve-2025-55130-node-js-permission-model-bypass-via-crafted-symlinks"},{"cve":"CVE-2026-21710","cvss":7.5,"epss":0.1307,"slug":"cve-2026-21710-node-js-denial-of-service-via-proto-header-in-req-headersdistinct","title":"Node.js denial of service via __proto__ header in req.headersDistinct","severity":"high","exploited":false,"published_at":"2026-03-30T20:16:18.21+00:00","url":"https://junglewise.ai/threats/cve-2026-21710-node-js-denial-of-service-via-proto-header-in-req-headersdistinct"},{"cve":"CVE-2015-8855","cvss":7.5,"epss":0.0649,"slug":"cve-2015-8855-node-js-semver-regular-expression-denial-of-service","title":"Node.js semver Regular Expression Denial of Service","severity":"high","exploited":false,"published_at":"2017-01-23T21:59:00.503+00:00","url":"https://junglewise.ai/threats/cve-2015-8855-node-js-semver-regular-expression-denial-of-service"},{"cve":"CVE-2015-8860","cvss":7.5,"epss":0.0491,"slug":"cve-2015-8860-node-js-tar-arbitrary-file-write-via-symlink-attack","title":"Node.js tar arbitrary file write via symlink attack","severity":"high","exploited":false,"published_at":"2017-01-23T21:59:00.69+00:00","url":"https://junglewise.ai/threats/cve-2015-8860-node-js-tar-arbitrary-file-write-via-symlink-attack"},{"cve":"CVE-2026-58043","cvss":7.5,"slug":"cve-2026-58043-node-js-permission-model-filesystem-access-bypass","title":"Node.js Permission Model filesystem access bypass","severity":"high","exploited":false,"published_at":"2026-07-30T06:25:55.31+00:00","url":"https://junglewise.ai/threats/cve-2026-58043-node-js-permission-model-filesystem-access-bypass"},{"cve":"CVE-2025-55131","cvss":7.1,"epss":0.0098,"slug":"cve-2025-55131-node-js-uninitialized-memory-exposure-in-vm-module-buffer","title":"Node.js uninitialized memory exposure in vm module buffer allocation","severity":"high","exploited":false,"published_at":"2026-01-20T21:16:03.32+00:00","url":"https://junglewise.ai/threats/cve-2025-55131-node-js-uninitialized-memory-exposure-in-vm-module-buffer"},{"cve":"CVE-2014-9772","cvss":6.1,"epss":0.0264,"slug":"cve-2014-9772-node-js-validator-xss-filter-bypass-via-hex-encoding","title":"Node.js validator XSS filter bypass via hex encoding","severity":"medium","exploited":false,"published_at":"2017-01-23T21:59:00.33+00:00","url":"https://junglewise.ai/threats/cve-2014-9772-node-js-validator-xss-filter-bypass-via-hex-encoding"},{"cve":"CVE-2013-7452","cvss":6.1,"epss":0.0205,"slug":"cve-2013-7452-node-js-validator-xss-filter-bypass-via-javascript-uri","title":"Node.js validator XSS filter bypass via javascript URI","severity":"medium","exploited":false,"published_at":"2017-01-23T21:59:00.207+00:00","url":"https://junglewise.ai/threats/cve-2013-7452-node-js-validator-xss-filter-bypass-via-javascript-uri"},{"cve":"CVE-2013-7454","cvss":6.1,"epss":0.0186,"slug":"cve-2013-7454-node-js-validator-xss-filter-bypass-via-nested-forbidden-strings","title":"Node.js validator XSS filter bypass via nested forbidden strings","severity":"medium","exploited":false,"published_at":"2017-01-23T21:59:00.267+00:00","url":"https://junglewise.ai/threats/cve-2013-7454-node-js-validator-xss-filter-bypass-via-nested-forbidden-strings"},{"cve":"CVE-2013-7453","cvss":6.1,"epss":0.0186,"slug":"cve-2013-7453-node-js-validator-xss-filter-bypass-via-ui-redressing","title":"Node.js validator XSS filter bypass via UI redressing","severity":"medium","exploited":false,"published_at":"2017-01-23T21:59:00.237+00:00","url":"https://junglewise.ai/threats/cve-2013-7453-node-js-validator-xss-filter-bypass-via-ui-redressing"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}