Direct Vulnerabilities

Known vulnerabilities in the nodejs24 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Resource Exhaustion

*
  • L
Improper Access Control

*
  • M
Reachable Assertion

<0:24.18.1-0.1.hum1
  • M
Reachable Assertion

*
  • L
Improper Access Control

<0:24.18.1-0.1.hum1
  • M
Resource Exhaustion

<0:24.18.1-0.1.hum1
  • M
HTTP Request Smuggling

<0:24.18.1-0.1.hum1
  • M
HTTP Request Smuggling

*
  • H
Allocation of Resources Without Limits or Throttling

<0:24.18.1-0.2.1.hum1
  • M
Time-of-check Time-of-use (TOCTOU)

<0:24.18.1-0.1.hum1
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • H
Expired Pointer Dereference

*
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

*
  • M
External Control of File Name or Path

*
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<0:24.18.1-0.1.hum1
  • M
Key Exchange without Entity Authentication

*
  • H
Resource Exhaustion

*
  • H
Resource Exhaustion

<0:24.18.1-0.1.hum1
  • L
External Control of File Name or Path

*
  • L
External Control of File Name or Path

<0:24.18.0-0.6.hum1
  • M
CVE-2026-69198

*
  • M
Improper Neutralization

<0:24.18.1-0.1.hum1
  • H
CVE-2026-69192

*
  • H
Information Exposure Through Caching

<0:24.18.1-0.1.hum1
  • M
Key Exchange without Entity Authentication

<0:24.18.1-0.1.hum1
  • M
Information Exposure Through Caching

<0:24.18.1-0.1.hum1
  • M
HTTP Request Smuggling

<0:24.18.1-0.1.hum1
  • M
CRLF Injection

<0:24.18.1-0.1.hum1
  • M
External Control of File Name or Path

<0:24.18.1-0.1.hum1
  • H
Allocation of Resources Without Limits or Throttling

<0:24.18.0-0.5.hum1
  • H
Allocation of Resources Without Limits or Throttling

*
  • H
Allocation of Resources Without Limits or Throttling

*
  • M
Incorrect Implementation of Authentication Algorithm

*
  • M
Incorrect Implementation of Authentication Algorithm

<0:24.18.1-0.1.hum1
  • H
Inefficient Regular Expression Complexity

<1:24.18.0-3.el10_2
  • H
Allocation of Resources Without Limits or Throttling

<1:24.18.0-3.el10_2
  • H
Unchecked Input for Loop Condition

<1:24.18.0-3.el10_2
  • M
Server-Side Request Forgery (SSRF)

*
  • M
Release of Invalid Pointer or Reference

<0:24.18.0-0.5.hum1
  • M
HTTP Request Smuggling

*
  • H
Allocation of Resources Without Limits or Throttling

<0:24.18.0-0.2.hum1
  • H
Inefficient Regular Expression Complexity

<0:24.18.0-0.2.hum1
  • H
Unchecked Input for Loop Condition

<0:24.18.0-0.3.hum1
  • M
Misinterpretation of Input

*
  • M
Improper Null Termination

*
  • M
Access of Resource Using Incompatible Type ('Type Confusion')

*
  • L
Improper Validation of Syntactic Correctness of Input

<1:24.18.0-1.el10_2
  • L
Improper Verification of Source of a Communication Channel

<1:24.18.0-1.el10_2
  • L
Incorrect Execution-Assigned Permissions

<1:24.18.0-1.el10_2
  • M
Improper Certificate Validation

<1:24.18.0-1.el10_2
  • H
Allocation of Resources Without Limits or Throttling

<1:24.18.0-1.el10_2
  • H
Cross-site Scripting (XSS)

<1:24.18.0-1.el10_2
  • M
Information Exposure

<1:24.18.0-1.el10_2
  • H
Allocation of Resources Without Limits or Throttling

<1:24.18.0-1.el10_2
  • M
Improper Null Termination

<1:24.18.0-1.el10_2
  • M
Authentication Bypass

<1:24.18.0-1.el10_2
  • M
Allocation of Resources Without Limits or Throttling

<1:24.18.0-1.el10_2
  • H
Authentication Bypass

<1:24.18.0-1.el10_2
  • M
Improper Validation of Syntactic Correctness of Input

<1:24.18.0-1.el10_2
  • H
Improper Verification of Source of a Communication Channel

<1:24.18.0-1.el10_2
  • H
Improper Certificate Validation

<1:24.18.0-1.el10_2
  • H
Inefficient Regular Expression Complexity

<0:24.18.0-0.2.hum1
  • M
Information Exposure

<0:24.18.0-0.1.hum1
  • H
Authentication Bypass

<0:24.18.0-0.1.hum1
  • H
Allocation of Resources Without Limits or Throttling

<0:24.18.0-0.1.hum1
  • M
Improper Null Termination

<0:24.18.0-0.2.hum1
  • M
Authentication Bypass

<0:24.18.0-0.2.hum1
  • L
Incorrect Use of Privileged APIs

<0:24.18.0-0.2.hum1
  • L
Incorrect Use of Privileged APIs

*
  • M
Allocation of Resources Without Limits or Throttling

<0:24.18.0-0.2.hum1
  • M
Improper Certificate Validation

<0:24.18.0-0.2.hum1
  • L
Incorrect Execution-Assigned Permissions

<0:24.18.0-0.2.hum1
  • M
Inefficient Regular Expression Complexity

<0:24.18.0-0.3.hum1
  • M
Resource Exhaustion

<0:24.16.0-1.hum1
  • H
Improper Verification of Source of a Communication Channel

<0:24.18.0-0.3.hum1
  • L
Improper Verification of Source of a Communication Channel

<0:24.18.0-0.3.hum1
  • H
Allocation of Resources Without Limits or Throttling

<0:24.18.0-0.3.hum1
  • H
Improper Certificate Validation

<0:24.18.0-0.3.hum1
  • L
Improper Validation of Syntactic Correctness of Input

<0:24.18.0-0.3.hum1
  • M
Improper Validation of Syntactic Correctness of Input

<0:24.18.0-0.3.hum1
  • M
CRLF Injection

<0:24.18.0-0.3.hum1
  • M
CRLF Injection

*
  • M
Allocation of Resources Without Limits or Throttling

<0:24.15.0-1.hum1
  • M
CRLF Injection

<0:24.18.0-0.3.hum1
  • M
Unchecked Input for Loop Condition

*
  • L
Incorrect Execution-Assigned Permissions

<0:24.14.1-4.hum1
  • M
Improper Preservation of Permissions

<0:24.14.1-4.hum1
  • M
Uncaught Exception

<0:24.14.1-4.hum1
  • M
Allocation of Resources Without Limits or Throttling

<0:24.14.1-4.hum1
  • H
Uncaught Exception

<0:24.14.1-4.hum1
  • M
Allocation of Resources Without Limits or Throttling

<0:24.14.1-4.hum1
  • H
Improper Preservation of Permissions

<0:24.14.1-4.hum1
  • H
Exposure of System Data to an Unauthorized Control Sphere

<0:24.14.1-4.hum1
  • M
Improper Preservation of Permissions

<0:24.14.1-4.hum1
  • M
Inefficient Regular Expression Complexity

<1:24.14.1-2.el10_1
  • L
Direct Request ('Forced Browsing')

<1:24.14.1-2.el10_1
  • H
Allocation of Resources Without Limits or Throttling

<1:24.14.1-2.el10_1
  • M
Allocation of Resources Without Limits or Throttling

<1:24.14.1-2.el10_1
  • H
Reachable Assertion

<1:24.14.1-2.el10_1
  • M
Missing Release of Resource after Effective Lifetime

<1:24.14.1-2.el10_1
  • M
Reversible One-Way Hash

<1:24.14.1-2.el10_1
  • M
Improper Handling of Inconsistent Special Elements

<1:24.14.1-2.el10_1
  • M
Information Exposure

<1:24.14.1-2.el10_1
  • M
Improper Verification of Source of a Communication Channel

<1:24.14.1-2.el10_1
  • L
Incorrect Execution-Assigned Permissions

<1:24.14.1-2.el10_1
  • M
HTTP Request Smuggling

<1:24.14.1-2.el10_1
  • M
CRLF Injection

<1:24.14.1-2.el10_1
  • H
Access of Resource Using Incompatible Type ('Type Confusion')

<1:24.14.1-2.el10_1
  • H
Uncaught Exception

<1:24.14.1-2.el10_1
  • H
Uncaught Exception

<1:24.14.1-2.el10_1
  • M
Improper Handling of Highly Compressed Data (Data Amplification)

<1:24.14.1-2.el10_1
  • M
Reversible One-Way Hash

<0:24.14.1-4.hum1
  • M
Inefficient Regular Expression Complexity

*
  • M
Executable Regular Expression Error

*
  • M
Inefficient Regular Expression Complexity

*
  • M
Inefficient Regular Expression Complexity

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • M
Time-of-check Time-of-use (TOCTOU)

*
  • M
Uncaught Exception

<1:24.13.0-1.el10_1
  • M
Improper Preservation of Permissions

<1:24.13.0-1.el10_1
  • H
Improper Preservation of Permissions

<1:24.13.0-1.el10_1
  • M
Allocation of Resources Without Limits or Throttling

<1:24.13.0-1.el10_1
  • H
Uncaught Exception

<1:24.13.0-1.el10_1
  • H
Exposure of System Data to an Unauthorized Control Sphere

<1:24.13.0-1.el10_1
  • M
Use After Free

*
  • L
OS Command Injection

*