Software Detail
Title
CVE
CRITICAL
HIGH
MEDIUM
LOW
CWE
Number of items displayed
node.js Number Of NVD 149 CRITICAL 13 HIGH 91 MEDIUM 44 LOW 1
URL https://nodejs.org/
Explanation Node.js releases a major version every 6 months.

The status of each version includes

Current : Added features

Active LTS : New stable features, bug fixes, and other updates are made by the LTS team.

Maintenance LTS : New features are added, major bug fixes and security updates are made by the LTS team. New features will only be added if they can be migrated to subsequent versions.

Odd-numbered releases (9, 11, etc.) will be Current and will be supported by the developers for 6 months only.
Even-numbered releases (10, 12, etc.) will be released after support for odd-numbered releases expires, and will be supported as Current for 6 months by the developers.
After 6 months of even-numbered releases, the system will move to Active LTS for 12 months and become generally available.
After the end of Active LTS, the system will move to Maintenance LTS for 12 months.
Even-numbered releases are usually guaranteed to have critical bugs fixed for a total of 30 months.

Only Active LTS and Maintenance LTS Node.js should be used in commercial products.
Tag
  • MIT License
  • Javascript

Add Information URL
No Type Name URL
1 https://nodejs.org/en/blog/
2 https://nodejs.org/en/blog/release/
3 https://nodejs.org/en/about/releases/
4 https://github.com/nodejs/Release

List Of Product  [ Click to show release history and vulnerability information ]
No Name Latest Version Release date Initial release Normal Support Security Support
Service Pack Support
Extended
for a fee
Critical High Medium Low
61 Node.js 22 v22.6.0 Aug. 6, 2024 June 11, 2024 0 0 0 0
62 Node.js 21 21.7.3 April 10, 2024 Oct. 17, 2023 0 0 0 0
63 Node.js 20 20.14.0 May 28, 2024 April 19, 2023 2 12 3 0
64 Node.js 19 19.7.0 Feb. 21, 2023 Oct. 18, 2022 0 5 2 0
65 Node.js 18 (LTS) 18.15.0 March 7, 2023 April 19, 2022 Oct. 18, 2023 April 30, 2025 2 15 8 0
66 Node.js 17 17.9.1 June 2, 2022 Oct. 19, 2021 April 1, 2022 June 1, 2022 0 3 2 0
67 Node.js 16 (LTS) 16.19.1 Feb. 16, 2023 April 20, 2021 Oct. 18, 2022 April 30, 2024 4 16 12 0
68 Node.js 15 15.14.0 April 6, 2021 Oct. 20, 2020 June 1, 2021 1 6 3 0
69 Node.js 14 (LTS) 14.21.3 Feb. 16, 2023 April 21, 2020 Oct. 18, 2021 April 30, 2023 3 22 13 0
70 Node.js 13 13.14.0 April 30, 2020 Oct. 22, 2019 June 1, 2020 2 1 0 0
71 Node.js 12 (LTS) 12.22.12 April 5, 2022 April 23, 2019 Oct. 21, 2019 April 30, 2022 4 24 9 0
72 Node.js 11 11.15.0 April 30, 2019 Oct. 23, 2018 June 1, 2019 0 4 5 0
73 Node.js 10 (LTS) 10.24.1 April 6, 2021 April 24, 2018 May 18, 2020 April 30, 2021 2 28 10 0
74 Node.js 9 9.11.2 June 12, 2018 Oct. 1, 2017 June 30, 2018 1 8 4 1
75 Node.js 8 (LTS) 8.17.0 Dec. 17, 2019 May 30, 2017 Dec. 31, 2018 Dec. 31, 2019 1 23 9 1
76 Node.js 7 7.10.1 July 11, 2017 Oct. 25, 2016 June 30, 2017 2 7 4 0
77 Node.js 6 (LTS) 6.17.1 April 3, 2019 Oct. 18, 2016 April 29, 2018 April 30, 2019 4 24 16 0
78 Node.js 5 5.12.0 June 23, 2016 Oct. 29, 2015 June 30, 2016 1 16 8 0
79 Node.js 4 (LTS) 4.9.1 March 30, 2018 Sept. 8, 2015 March 30, 2017 April 30, 2018 April 1, 2017 6 25 13 0
80 Node.js 3.0 3.0.0 0 5 3 0
81 Node.js 2.0 2.0.2 0 5 3 0
82 Node.js 1 1.1.0 0 10 10 0
83 Node.js 0 0.0.6 2 22 16 0
NVD Vulnerability Information
  • CRITICAL
  • HIGH
  • MEDIUM
  • LOW
No CVSS3
CVSS2
Level
Attach Vector
Title CWE CVE cpe23Uri or higher or less more than less than Update date
Published date
Show Affected Exploit
PoC
Search
61 7.5
5.0
HIGH
Network
In nghttp2 before version 1.41.0, the overly large HTTP/2 SETTINGS frame payload causes denial of service. The proof of concept attack involves a malicious client constructing a SETTINGS frame with a… - CVE-2020-11080 cpe:2.3:a:nodejs:node.js:*:* 10.13.0
12.13.0
10.0.0
12.0.0
14.0.0


10.12.0
12.12.0
14.4.0




10.21.0
12.18.0


2024-11-21 13:56
2020-06-4
Show GitHub Exploit DB Packet Storm
62 8.8
6.8
HIGH
Network
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeString::doAppend() fun… CWE-787
CWE-190
 Out-of-bounds Write
 Integer Overflow or Wraparound
CVE-2020-10531 cpe:2.3:a:nodejs:node.js:*:* 10.13.0
10.0.0

10.12.0

10.21.0
2024-11-21 13:55
2020-03-13
Show GitHub Exploit DB Packet Storm
63 8.1
6.8
HIGH
Network
The uv_rwlock_t fallback implementation for Windows XP and Server 2003 in libuv before 1.7.4 does not properly prevent threads from releasing the locks of other threads, which allows attackers to cau… CWE-362
Race Condition
CVE-2014-9748 cpe:2.3:a:nodejs:node.js:*:* 0.12.0
0.10.0


0.12.15
0.10.46
2024-11-21 11:21
2020-02-12
Show GitHub Exploit DB Packet Storm
64 9.8
7.5
CRITICAL
Network
Including trailing white space in HTTP header values in Nodejs 10, 12, and 13 causes bypass of authorization based on header value comparisons NVD-CWE-Other
CVE-2019-15606 cpe:2.3:a:nodejs:node.js:*:* 12.0.0
10.0.0
13.0.0




12.15.0
10.19.0
13.8.0
2024-11-21 13:29
2020-02-8
Show GitHub Exploit DB Packet Storm
65 9.8
7.5
CRITICAL
Network
HTTP request smuggling in Node.js 10, 12, and 13 causes malicious payload delivery when transfer-encoding is malformed CWE-444
HTTP Request Smuggling
CVE-2019-15605 cpe:2.3:a:nodejs:node.js:*:* 12.0.0
10.0.0
13.0.0




12.15.0
10.19.0
13.8.0
2024-11-21 13:29
2020-02-8
Show GitHub Exploit DB Packet Storm
66 7.5
5.0
HIGH
Network
Improper Certificate Validation in Node.js 10, 12, and 13 causes the process to abort when sending a crafted X.509 certificate CWE-295
Improper Certificate Validation 
CVE-2019-15604 cpe:2.3:a:nodejs:node.js:*:* 12.0.0
10.0.0
13.0.0




12.15.0
10.19.0
13.8.0
2024-11-21 13:29
2020-02-8
Show GitHub Exploit DB Packet Storm
67 7.5
7.8
HIGH
Network
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and without the end-of-s… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2019-9518 cpe:2.3:a:nodejs:node.js:*:* 10.13.0
8.9.0
8.0.0
10.0.0
12.0.0


8.8.1
10.12.0




10.16.3
8.16.1


12.8.1
2024-11-21 13:51
2019-08-14
Show GitHub Exploit DB Packet Storm
68 7.5
7.8
HIGH
Network
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer can send without const… CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2019-9517 cpe:2.3:a:nodejs:node.js:*:* 10.13.0
8.9.0
8.0.0
10.0.0
12.0.0


8.8.1
10.12.0




10.16.3
8.16.1


12.8.1
2024-11-21 13:51
2019-08-14
Show GitHub Exploit DB Packet Storm
69 7.5
7.8
HIGH
Network
Some HTTP/2 implementations are vulnerable to ping floods, potentially leading to a denial of service. The attacker sends continual pings to an HTTP/2 peer, causing the peer to build an internal queu… CWE-400
 Uncontrolled Resource Consumption
CVE-2019-9512 cpe:2.3:a:nodejs:node.js:*:* 10.13.0
8.9.0
8.0.0
10.0.0
12.0.0


8.8.1
10.12.0




10.16.3
8.16.1


12.8.1
2024-11-21 13:51
2019-08-14
Show GitHub Exploit DB Packet Storm
70 6.5
6.8
MEDIUM
Network
Some HTTP/2 implementations are vulnerable to a header leak, potentially leading to a denial of service. The attacker sends a stream of headers with a 0-length header name and 0-length header value, … CWE-770
 Allocation of Resources Without Limits or Throttling
CVE-2019-9516 cpe:2.3:a:nodejs:node.js:*:* 8.0.0
10.0.0
12.0.0




8.16.1
10.16.3
12.8.1
2024-11-21 13:51
2019-08-14
Show GitHub Exploit DB Packet Storm