nodejs-npm vulnerabilities

Direct Vulnerabilities

Known vulnerabilities in the nodejs-npm package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • M
Inefficient Regular Expression Complexity

<1:10.8.2-1.18.20.5.1.amzn2023.0.1
  • M
Resource Exhaustion

<1:10.7.0-1.18.20.4.1.amzn2023.0.1
  • M
Incorrect Authorization

<1:10.5.0-1.18.20.2.1.amzn2023.0.1
  • M
HTTP Request Smuggling

<1:10.5.0-1.18.20.2.1.amzn2023.0.1
  • M
CVE-2024-30261

<1:10.5.0-1.18.20.2.1.amzn2023.0.1
  • H
Resource Exhaustion

<1:9.8.1-1.18.18.2.1.amzn2023.0.4
  • H
Detection of Error Condition Without Action

<1:9.8.1-1.18.18.2.1.amzn2023.0.4
  • H
Resource Exhaustion

<1:9.8.1-1.18.18.2.1.amzn2023.0.2
  • M
Buffer Under-read

<1:9.8.1-1.18.18.2.1.amzn2023.0.3
  • M
CVE-2024-24758

<1:9.8.1-1.18.18.2.1.amzn2023.0.3
  • H
Arbitrary Code Injection

<1:9.8.1-1.18.18.2.1.amzn2023.0.2
  • M
Resource Exhaustion

<1:9.8.1-1.18.18.2.1.amzn2023.0.3
  • H
Improper Validation of Integrity Check Value

<1:9.8.1-1.18.18.2.1.amzn2023.0.1
  • H
Information Exposure

<1:9.8.1-1.18.18.2.1.amzn2023.0.1
  • H
Arbitrary Code Injection

<1:9.8.1-1.18.18.2.1.amzn2023.0.1
  • H
Resource Exhaustion

<1:9.8.1-1.18.18.0.1.amzn2023.0.1