脆弱性一覧

CVE / GHSA / KEV / OSV を統合監視。タグ・カテゴリで絞り込み可能。

フィルタ中: タグ: nodejs クリア
ID タイトル
CVE-2026-73222 Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds t...
Claude Code Templates is a CLI tool for configuring and monitoring Claude Code. Prior to 1.29.4, the Claude Code Studio server launched by the --studio option in cli-tool/src/sandbox-server.js binds to all interfaces on port 3444, permits cross-origin requests, and requires no authentication. The PO...
CVE-2026-58043 nodejs の脆弱性 (CVE-2026-58043)
nodejs に 脆弱性 (CVE-2026-58043) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-56847 nodejs の脆弱性 (CVE-2026-56847)
nodejs に 脆弱性 (CVE-2026-56847) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-56850 nodejs に 認証バイパス (CVE-2026-56850)
nodejs に 認証バイパス (CVE-2026-56850) が存在。データの不正な改ざんを許す可能性があります。
CVE-2026-15157 undici の脆弱性 (CVE-2026-15157)
undici に 脆弱性 (CVE-2026-15157) が存在。不正な操作・情報露出のリスクがあります。``body.type`` 経由で攻撃可能。対策: `6.24.0` 以上に更新。
CVE-2026-14643 undici の脆弱性 (CVE-2026-14643)
undici に 脆弱性 (CVE-2026-14643) が存在。機密情報が外部に流出する可能性があります。``private`` 経由で攻撃可能。対策: `8.9.0` 以上に更新。
CVE-2026-16728 undici の脆弱性 (CVE-2026-16728)
undici に 脆弱性 (CVE-2026-16728) が存在。不正な操作・情報露出のリスクがあります。対策: `8.9.0` 以上に更新。
CVE-2026-16729 undici の脆弱性 (CVE-2026-16729)
undici に 脆弱性 (CVE-2026-16729) が存在。不正な操作・情報露出のリスクがあります。``setCookie`` 経由で攻撃可能。対策: `8.9.0` 以上に更新。
CVE-2026-13697 undici に 情報漏洩 (CVE-2026-13697)
undici に 脆弱性 (CVE-2026-13697) が存在。機密情報が外部に流出する可能性があります。``private`` 経由で攻撃可能。対策: `8.9.0` 以上に更新。
CVE-2026-15074 @fastify/static vulnerable to route guard bypass via path traversal
@fastify/static vulnerable to route guard bypass via path traversal
CVE-2026-16158 Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destinat...
Impact: @fastify/reply-from versions from 8.3.1 up to but not including 12.6.4 build the internal URL cache key by concatenating the destination and source path without a delimiter. Different destination and source pairs can therefore produce the same key while resolving to different upstream URLs....
CVE-2026-15631 Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in...
Impact: @fastify/http-proxy versions from 9.4.0 up to and including 11.5.0 fail to validate the resolved WebSocket destination path against the configured rewrite prefix. The WebSocket routing path in WebSocketProxy.findUpstream resolves the destination via the WHATWG URL constructor, which collapse...
CVE-2026-48934 node の脆弱性 (CVE-2026-48934)
node に 脆弱性 (CVE-2026-48934) が存在。不正な操作・情報露出のリスクがあります。対策: `22.23.0, 24.17.0, 26.3.1` 以上に更新。
CVE-2026-48935 node の脆弱性 (CVE-2026-48935)
node に 脆弱性 (CVE-2026-48935) が存在。不正な操作・情報露出のリスクがあります。対策: `22.23.0, 24.17.0, 26.3.1` 以上に更新。
CVE-2026-48936 node の脆弱性 (CVE-2026-48936)
node に 脆弱性 (CVE-2026-48936) が存在。不正な操作・情報露出のリスクがあります。対策: `26.3.1` 以上に更新。
CVE-2026-48619 node の脆弱性 (CVE-2026-48619)
node に 脆弱性 (CVE-2026-48619) が存在。不正な操作・情報露出のリスクがあります。対策: `22.23.0, 24.17.0, 26.3.1` 以上に更新。
CVE-2026-48933 nodejs の脆弱性 (CVE-2026-48933)
nodejs に 脆弱性 (CVE-2026-48933) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-48615 node の脆弱性 (CVE-2026-48615)
node に 脆弱性 (CVE-2026-48615) が存在。機密情報が外部に流出する可能性があります。``ERR_PROXY_TUNNEL`` 経由で攻撃可能。対策: `22.23.0, 24.17.0, 26.3.1` 以上に更新。
CVE-2026-48930 node の脆弱性 (CVE-2026-48930)
node に 脆弱性 (CVE-2026-48930) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。対策: `22.23.0, 24.17.0, 26.3.1` 以上に更新。
CVE-2026-48928 node の脆弱性 (CVE-2026-48928)
node に 脆弱性 (CVE-2026-48928) が存在。不正な操作・情報露出のリスクがあります。対策: `22.23.0, 24.17.0, 26.3.1` 以上に更新。
CVE-2026-48618 nodejs の脆弱性 (CVE-2026-48618)
nodejs に 脆弱性 (CVE-2026-48618) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-54639 Style Dictionary - Prototype Pollution in convertTokenData utility function
Style Dictionary - Prototype Pollution in convertTokenData utility function
CVE-2026-48931 node の脆弱性 (CVE-2026-48931)
node に 脆弱性 (CVE-2026-48931) が存在。不正な操作・情報露出のリスクがあります。対策: `22.23.0, 24.17.0, 26.3.1` 以上に更新。
CVE-2026-48937 nodejs の脆弱性 (CVE-2026-48937)
nodejs に 脆弱性 (CVE-2026-48937) が存在。不正な操作・情報露出のリスクがあります。``GOAWAY`` 経由で攻撃可能。
CVE-2026-48617 nodejs の脆弱性 (CVE-2026-48617)
nodejs に 脆弱性 (CVE-2026-48617) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-9697 undici の脆弱性 (CVE-2026-9697)
undici に 脆弱性 (CVE-2026-9697) が存在。機密情報が外部に流出する可能性があります。``ProxyAgent`` 経由で攻撃可能。対策: `8.5.0` 以上に更新。
CVE-2026-9679 undici の脆弱性 (CVE-2026-9679)
undici に 脆弱性 (CVE-2026-9679) が存在。データの不正な改ざんを許す可能性があります。``parseSetCookie`` 経由で攻撃可能。対策: `8.5.0` 以上に更新。
CVE-2026-9678 undici の脆弱性 (CVE-2026-9678)
undici に 脆弱性 (CVE-2026-9678) が存在。機密情報が外部に流出する可能性があります。``private`` 経由で攻撃可能。対策: `8.5.0` 以上に更新。
CVE-2026-6733 undici の脆弱性 (CVE-2026-6733)
undici に 脆弱性 (CVE-2026-6733) が存在。不正な操作・情報露出のリスクがあります。対策: `8.5.0` 以上に更新。
CVE-2026-6734 undici の脆弱性 (CVE-2026-6734)
undici に 脆弱性 (CVE-2026-6734) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``Socks5ProxyAgent`` 経由で攻撃可能。対策: `8.2.0` 以上に更新。
CVE-2026-11525 undici の脆弱性 (CVE-2026-11525)
undici に 脆弱性 (CVE-2026-11525) が存在。不正な操作・情報露出のリスクがあります。``SameSite`` 経由で攻撃可能。対策: `8.5.0` 以上に更新。
CVE-2026-9675 undici の脆弱性 (CVE-2026-9675)
undici に 脆弱性 (CVE-2026-9675) が存在。不正な操作・情報露出のリスクがあります。``maxPayloadSize`` 経由で攻撃可能。対策: `8.5.0` 以上に更新。
CVE-2026-12151 undici の脆弱性 (CVE-2026-12151)
undici に 脆弱性 (CVE-2026-12151) が存在。不正な操作・情報露出のリスクがあります。``maxPayloadSize`` 経由で攻撃可能。対策: `8.5.0` 以上に更新。
CVE-2026-53864 OpenClaw: Host environment sanitizer missed two Node.js control variables
OpenClaw: Host environment sanitizer missed two Node.js control variables
CVE-2026-44313 ssrf に SSRF (サーバー側リクエスト偽造) (CVE-2026-44313)
ssrf に SSRF (CVE-2026-44313) が存在。機密情報が外部に流出する可能性があります。`GET /api/v1/archives/{linkId}` 経由で攻撃可能。
CVE-2026-41512 gem に コードインジェクション (CVE-2026-41512)
gem に コードインジェクション (CVE-2026-41512) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。`POST /targets/auto_detect_selectors` 経由で攻撃可能。
CVE-2026-43944 electerm の脆弱性 (CVE-2026-43944)
electerm に 脆弱性 (CVE-2026-43944) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``opts`` 経由で攻撃可能。対策: `> 3.8.8` 以上に更新。
CVE-2025-63706 npm に コードインジェクション (CVE-2025-63706)
npm に コードインジェクション (CVE-2025-63706) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。
CVE-2026-26956 vm2-project の脆弱性 (CVE-2026-26956)
vm2-project に 脆弱性 (CVE-2026-26956) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``catch`` 経由で攻撃可能。
CVE-2026-24118 vm2-project に コードインジェクション (CVE-2026-24118)
vm2-project に コードインジェクション (CVE-2026-24118) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``__lookupGetter__`` 経由で攻撃可能。
CVE-2026-24120 vm2-project に コードインジェクション (CVE-2026-24120)
vm2-project に コードインジェクション (CVE-2026-24120) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``resetPromiseSpecies`` 経由で攻撃可能。
CVE-2026-24781 vm2-project に コードインジェクション (CVE-2026-24781)
vm2-project に コードインジェクション (CVE-2026-24781) が存在。悪用されるとシステム全体を乗っ取られる可能性があります。``inspect`` 経由で攻撃可能。
CVE-2026-21710 node の脆弱性 (CVE-2026-21710)
node に 脆弱性 (CVE-2026-21710) が存在。不正な操作・情報露出のリスクがあります。``TypeError`` 経由で攻撃可能。対策: `20.20.2, 22.22.2, 24.14.1, 25.8.2` 以上に更新。
CVE-2026-21717 nodejs の脆弱性 (CVE-2026-21717)
nodejs に 脆弱性 (CVE-2026-21717) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-21716 nodejs の脆弱性 (CVE-2026-21716)
nodejs に 脆弱性 (CVE-2026-21716) が存在。不正な操作・情報露出のリスクがあります。``FileHandle`` 経由で攻撃可能。
CVE-2026-21715 nodejs の脆弱性 (CVE-2026-21715)
nodejs に 脆弱性 (CVE-2026-21715) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-21714 nodejs の脆弱性 (CVE-2026-21714)
nodejs に 脆弱性 (CVE-2026-21714) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-21711 nodejs の脆弱性 (CVE-2026-21711)
nodejs に 脆弱性 (CVE-2026-21711) が存在。不正な操作・情報露出のリスクがあります。
CVE-2026-21713 nodejs の脆弱性 (CVE-2026-21713)
nodejs に 脆弱性 (CVE-2026-21713) が存在。機密情報が外部に流出する可能性があります。
CVE-2026-21712 nodejs の脆弱性 (CVE-2026-21712)
nodejs に 脆弱性 (CVE-2026-21712) が存在。不正な操作・情報露出のリスクがあります。

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →