← Back

Nodejs

nodejs

202 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Node.js
node.js
Undici
undici

CVEs (202)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
4Debian
GoogleNodejs+1 more
4Chrome
Debian LinuxNode.js+1 more
Apr 29, 2026
Jul 31, 2013
N/A· v4
N/A· v3
7.5 HIGH· v2
Google V8, as used in Google Chrome before 28.0.1500.95, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors that leverage "type confusion."
1Nodejs
1Node.js
Apr 29, 2026
Aug 13, 2012
N/A· v4
N/A· v3
6.4 MEDIUM· v2
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header con...Show more
The Update method in src/node_http_parser.cc in Node.js before 0.6.17 and 0.7 before 0.7.8 does not properly check the length of a string, which allows remote attackers to obtain sensitive information (request header contents) and possibly spoof HTTP headers via a zero length string.Show less