Direct Vulnerabilities

Known vulnerabilities in the nodejs26 package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • M
Missing Handler

*
  • M
Missing Handler

*
  • H
Origin Validation Error

<0:26.7.0-1.5.2.hum1
  • H
Origin Validation Error

*
  • H
NULL Pointer Dereference

*
  • H
NULL Pointer Dereference

*
  • H
Improper Certificate Validation

*
  • H
Improper Certificate Validation

*
  • M
Improper Handling of Length Parameter Inconsistency

<0:26.7.0-1.5.2.hum1
  • M
Improper Handling of Length Parameter Inconsistency

*
  • M
Improper Handling of Highly Compressed Data (Data Amplification)

<0:26.7.0-1.5.2.hum1
  • M
Improper Handling of Highly Compressed Data (Data Amplification)

*
  • M
Information Exposure Through Caching

<0:26.7.0-1.5.2.hum1
  • M
Information Exposure Through Caching

*
  • M
Detection of Error Condition Without Action

<0:26.7.0-1.5.2.hum1
  • M
Detection of Error Condition Without Action

*
  • M
Improper Update of Reference Count

<0:26.7.0-1.5.2.hum1
  • M
Improper Update of Reference Count

*
  • H
Improper Validation of Specified Type of Input

*
  • L
Allocation of Resources Without Limits or Throttling

*
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

*
  • M
Improper Output Neutralization for Logs

*
  • M
Reachable Assertion

<0:26.7.0-1.5.1.hum1
  • L
Improper Access Control

<0:26.5.1-1.5.hum1
  • M
Resource Exhaustion

<0:26.7.0-1.5.1.hum1
  • M
HTTP Request Smuggling

<0:26.7.0-1.5.1.hum1
  • H
Allocation of Resources Without Limits or Throttling

<0:26.7.0-1.5.2.hum1
  • M
Time-of-check Time-of-use (TOCTOU)

<0:26.7.0-1.5.1.hum1
  • H
Incorrect Behavior Order: Authorization Before Parsing and Canonicalization

<0:26.5.1-1.5.hum1
  • L
External Control of File Name or Path

<0:26.5.0-1.5.hum1
  • M
Improper Neutralization

<0:26.5.1-1.5.hum1
  • H
Information Exposure Through Caching

<0:26.5.1-1.5.hum1
  • M
Key Exchange without Entity Authentication

<0:26.5.1-1.5.hum1
  • M
Information Exposure Through Caching

<0:26.5.1-1.5.hum1
  • M
HTTP Request Smuggling

<0:26.5.1-1.5.hum1
  • M
CRLF Injection

<0:26.5.1-1.5.hum1
  • M
External Control of File Name or Path

<0:26.5.1-1.5.hum1
  • H
Allocation of Resources Without Limits or Throttling

<0:26.5.0-1.4.hum1
  • M
Incorrect Implementation of Authentication Algorithm

<0:26.5.1-1.5.hum1
  • H
Allocation of Resources Without Limits or Throttling

<0:26.4.0-1.3.hum1
  • H
Inefficient Regular Expression Complexity

<0:26.4.0-1.3.hum1
  • H
Unchecked Input for Loop Condition

<0:26.4.0-1.4.hum1
  • H
Inefficient Regular Expression Complexity

<0:26.4.0-1.3.hum1
  • M
Information Exposure

<0:26.4.0-1.2.hum1
  • H
Authentication Bypass

<0:26.4.0-1.2.hum1
  • H
Allocation of Resources Without Limits or Throttling

<0:26.4.0-1.2.hum1
  • M
Improper Null Termination

<0:26.4.0-1.3.hum1
  • M
Authentication Bypass

<0:26.4.0-1.3.hum1
  • L
Incorrect Use of Privileged APIs

<0:26.4.0-1.3.hum1
  • M
Allocation of Resources Without Limits or Throttling

<0:26.4.0-1.3.hum1
  • M
Improper Certificate Validation

<0:26.4.0-1.3.hum1
  • L
Incorrect Execution-Assigned Permissions

<0:26.4.0-1.3.hum1
  • M
Inefficient Regular Expression Complexity

<0:26.4.0-1.3.hum1
  • M
Resource Exhaustion

<0:26.3.0-1.2.hum1
  • H
Improper Verification of Source of a Communication Channel

<0:26.3.0-1.2.hum1
  • L
Improper Verification of Source of a Communication Channel

<0:26.5.0-1.3.hum1
  • H
Allocation of Resources Without Limits or Throttling

<0:26.5.0-1.3.hum1
  • H
Improper Certificate Validation

<0:26.3.0-1.2.hum1
  • L
Improper Validation of Syntactic Correctness of Input

<0:26.5.0-1.5.hum1
  • M
Improper Validation of Syntactic Correctness of Input

<0:26.3.0-1.2.hum1
  • M
CRLF Injection

<0:26.5.0-1.3.hum1
  • M
Allocation of Resources Without Limits or Throttling

<0:26.3.0-1.2.hum1
  • M
CRLF Injection

*