{"schema_version":1,"title":"NestJS vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 7 vulnerabilities in NestJS: 0 in the last 7 days and 0 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-54281, was published on 22 June 2026. 2 technologies have a page of their own.","url":"https://junglewise.ai/threats/vendors/nestjs","json_url":"https://junglewise.ai/threats/vendors/nestjs.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/nestjs","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":2,"all_time":7,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":5},"latest":[{"cve":"CVE-2026-54281","cvss":4,"epss":0.005,"slug":"cve-2026-54281-nestjs-authentication-bypass-in-nestjs-platform-fastify-via","title":"NestJS authentication bypass in @nestjs/platform-fastify via trailing slash","severity":"high","exploited":false,"published_at":"2026-06-22T22:16:49.433+00:00","url":"https://junglewise.ai/threats/cve-2026-54281-nestjs-authentication-bypass-in-nestjs-platform-fastify-via"},{"cve":"CVE-2026-40879","cvss":7.5,"epss":0.0046,"slug":"cve-2026-40879-nest-affected-by-dos-via-recursive-handledata-in-jsonsocket-tcp","title":"Nest Affected by DoS via Recursive handleData in JsonSocket (TCP Transport)","severity":"high","exploited":false,"published_at":"2026-04-14T00:15:09+00:00","url":"https://junglewise.ai/threats/cve-2026-40879-nest-affected-by-dos-via-recursive-handledata-in-jsonsocket-tcp"},{"cve":"CVE-2026-33011","cvss":4,"epss":0.0048,"slug":"cve-2026-33011-nestjs-platform-fastify-head-request-middleware-bypass","title":"NestJS platform-fastify HEAD request middleware bypass","severity":"medium","exploited":false,"published_at":"2026-03-17T18:38:38+00:00","url":"https://junglewise.ai/threats/cve-2026-33011-nestjs-platform-fastify-head-request-middleware-bypass"},{"cve":"CVE-2026-2293","cvss":9.8,"epss":0.0067,"slug":"cve-2026-2293-nestjs-auth-bypass-in-nestjs-platform-fastify","title":"NestJS auth bypass in @nestjs/platform-fastify","severity":"critical","exploited":false,"published_at":"2026-02-27T17:16:33.357+00:00","url":"https://junglewise.ai/threats/cve-2026-2293-nestjs-auth-bypass-in-nestjs-platform-fastify"},{"cve":"CVE-2025-69211","cvss":4,"epss":0.0038,"slug":"cve-2025-69211-nestjs-fastify-url-encoding-middleware-bypass","title":"NestJS Fastify URL encoding middleware bypass","severity":"medium","exploited":false,"published_at":"2025-12-30T15:32:44+00:00","url":"https://junglewise.ai/threats/cve-2025-69211-nestjs-fastify-url-encoding-middleware-bypass"},{"cve":"CVE-2025-54782","cvss":4,"epss":0.5132,"slug":"cve-2025-54782-nestjs-devtools-integration-sandbox-escape-and-rce","title":"NestJS devtools-integration sandbox escape and RCE","severity":"medium","exploited":false,"published_at":"2025-08-01T18:43:13+00:00","url":"https://junglewise.ai/threats/cve-2025-54782-nestjs-devtools-integration-sandbox-escape-and-rce"},{"cve":"CVE-2023-26108","cvss":3.1,"epss":0.0071,"slug":"cve-2023-26108-nestjs-core-information-exposure-in-streamablefile-pipe","title":"NestJS Core information exposure in StreamableFile pipe","severity":"low","exploited":false,"published_at":"2023-03-06T06:30:18+00:00","url":"https://junglewise.ai/threats/cve-2023-26108-nestjs-core-information-exposure-in-streamablefile-pipe"}],"vendor":{"hub":true,"name":"NestJS","slug":"nestjs","homepage":"https://nestjs.com/","description":"The organization responsible for the development of the NestJS framework.","url":"https://junglewise.ai/threats/vendors/nestjs"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-2293","cvss":9.8,"epss":0.0067,"slug":"cve-2026-2293-nestjs-auth-bypass-in-nestjs-platform-fastify","title":"NestJS auth bypass in @nestjs/platform-fastify","severity":"critical","exploited":false,"published_at":"2026-02-27T17:16:33.357+00:00","url":"https://junglewise.ai/threats/cve-2026-2293-nestjs-auth-bypass-in-nestjs-platform-fastify"},{"cve":"CVE-2026-40879","cvss":7.5,"epss":0.0046,"slug":"cve-2026-40879-nest-affected-by-dos-via-recursive-handledata-in-jsonsocket-tcp","title":"Nest Affected by DoS via Recursive handleData in JsonSocket (TCP Transport)","severity":"high","exploited":false,"published_at":"2026-04-14T00:15:09+00:00","url":"https://junglewise.ai/threats/cve-2026-40879-nest-affected-by-dos-via-recursive-handledata-in-jsonsocket-tcp"},{"cve":"CVE-2026-54281","cvss":4,"epss":0.005,"slug":"cve-2026-54281-nestjs-authentication-bypass-in-nestjs-platform-fastify-via","title":"NestJS authentication bypass in @nestjs/platform-fastify via trailing slash","severity":"high","exploited":false,"published_at":"2026-06-22T22:16:49.433+00:00","url":"https://junglewise.ai/threats/cve-2026-54281-nestjs-authentication-bypass-in-nestjs-platform-fastify-via"},{"cve":"CVE-2025-54782","cvss":4,"epss":0.5132,"slug":"cve-2025-54782-nestjs-devtools-integration-sandbox-escape-and-rce","title":"NestJS devtools-integration sandbox escape and RCE","severity":"medium","exploited":false,"published_at":"2025-08-01T18:43:13+00:00","url":"https://junglewise.ai/threats/cve-2025-54782-nestjs-devtools-integration-sandbox-escape-and-rce"},{"cve":"CVE-2026-33011","cvss":4,"epss":0.0048,"slug":"cve-2026-33011-nestjs-platform-fastify-head-request-middleware-bypass","title":"NestJS platform-fastify HEAD request middleware bypass","severity":"medium","exploited":false,"published_at":"2026-03-17T18:38:38+00:00","url":"https://junglewise.ai/threats/cve-2026-33011-nestjs-platform-fastify-head-request-middleware-bypass"},{"cve":"CVE-2025-69211","cvss":4,"epss":0.0038,"slug":"cve-2025-69211-nestjs-fastify-url-encoding-middleware-bypass","title":"NestJS Fastify URL encoding middleware bypass","severity":"medium","exploited":false,"published_at":"2025-12-30T15:32:44+00:00","url":"https://junglewise.ai/threats/cve-2025-69211-nestjs-fastify-url-encoding-middleware-bypass"},{"cve":"CVE-2023-26108","cvss":3.1,"epss":0.0071,"slug":"cve-2023-26108-nestjs-core-information-exposure-in-streamablefile-pipe","title":"NestJS Core information exposure in StreamableFile pipe","severity":"low","exploited":false,"published_at":"2023-03-06T06:30:18+00:00","url":"https://junglewise.ai/threats/cve-2023-26108-nestjs-core-information-exposure-in-streamablefile-pipe"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"NestJS","slug":"nest","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/nest"},{"name":"NestJS Platform Fastify","slug":"platform-fastify","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/platform-fastify"}]}