MikeTrendsTrends right now

search

Node.js

Trends

  1. 1
    Fastify vulnerability EUVD-2026-70998 rated 7.5 publishedโ–ผ๐Ÿšจ EUVD-2026-70998 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: fastify ๐Ÿข Vendor: fastify ๐Ÿ“… Updated: 2026-09-30 ๐Ÿ“ fastify vulneMmastodonTechnologyCybersecurity01 d ago

    A new vulnerability, EUVD-2026-70998, has been recorded for Fastify, the popular Node.js web framework. The flaw, rated 7.5 out of 10 on CVSS v3.1, allows a header validation bypass caused by incomplete schema case normalization. The entry in the European vulnerability database was updated on 30 September 2026. Security teams using Fastify are expected to review the advisory and check whether their deployments are affected.

  2. 2
    Fastify vulnerability EUVD-2026-70989 scores 7.5โ–ผ๐Ÿšจ EUVD-2026-70989 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: fastify ๐Ÿข Vendor: fastify ๐Ÿ“… Updated: 2026-09-30 ๐Ÿ“ fastify vulneMmastodonTechnologyCybersecurity01 d ago

    A medium-high severity vulnerability, EUVD-2026-70989, has been catalogued in Fastify, the popular Node.js web framework. Rated 7.5 under CVSS v3.1, the flaw allows request validation bypass when boolean false schemas are skipped, potentially letting malformed requests through unchecked. The advisory was updated on 30 September 2026, and security teams using Fastify are being urged to review their validation logic and apply patches.

  3. 3
    Fastify vulnerability allows authentication bypass via malformed URLsโ–ผ๐Ÿšจ EUVD-2026-70988 ๐Ÿ“Š Score: 7.5/10 (CVSS v3.1) ๐Ÿ“ฆ Product: fastify ๐Ÿข Vendor: fastify ๐Ÿ“… Updated: 2026-09-30 ๐Ÿ“ fastify vulneMmastodonTechnologyCybersecurity01 d ago

    A newly catalogued vulnerability, EUVD-2026-70988, affects the Fastify web framework, rated 7.5 out of 10 on the CVSS v3.1 scale. The flaw allows authentication bypass when malformed URLs reach encapsulated not-found handlers, meaning requests intended to be blocked could slip through route protections. Fastify is a widely used Node.js framework, so developers running exposed services are being urged to review the advisory and update to a patched version.

  4. 4
    Graceful shutdown handlers fail when kill -9 strikesโ—You write a graceful shutdown handler in Node.js, Python, or Go. You catch SIGTERM and SIGINT , close your database connMmastodonTechnologySoftware41 d ago

    Developers are discussing a common gap in software reliability: applications written in Node.js, Python, or Go often include shutdown handlers that catch SIGTERM and SIGINT, close database connections, flush files, and exit cleanly. But these handlers never run when a process receives SIGINT's harsher cousin, kill -9, or when Kubernetes force-kills a container after a timeout, leaving cleanup unfinished and potentially corrupting state.

  5. 5
    Critical 10/10 vulnerability flagged in vm2 sandbox libraryโ—๐Ÿšจ EUVD-2026-81591 ๐Ÿ“Š Score: 10.0/10 (CVSS v3.1) ๐Ÿ“ฆ Product: vm2 ๐Ÿข Vendor: patriksimek ๐Ÿ“… Updated: 2026-10-01 ๐Ÿ“ vm2 NodeVM cMmastodonTechnologyCybersecurity022 h ago

    A maximum-severity security flaw, tracked as EUVD-2026-81591, has been disclosed in vm2, the Node.js sandbox library maintained by Patrik Simek. The vulnerability, rated 10.0 out of 10 under CVSS v3.1, allows the NodeVM component to replace the host process TLS trust store, potentially undermining certificate validation. The advisory was updated on 1 October 2026 and appears in the EU vulnerability database.

  6. 6
    Critical vm2 sandbox escape vulnerability flagged in Node.jsโ—๐Ÿšจ EUVD-2026-81593 ๐Ÿ“Š Score: 9.3/10 (CVSS v3.1) ๐Ÿ“ฆ Product: vm2 ๐Ÿข Vendor: patriksimek ๐Ÿ“… Updated: 2026-10-01 ๐Ÿ“ vm2 sandbox eMmastodonTechnologyCybersecurity022 h ago

    A high-severity vulnerability, EUVD-2026-81593, has been catalogued affecting vm2, the JavaScript sandbox library maintained by Patrik Simek. The flaw scores 9.3 out of 10 on CVSS v3.1 and allows a sandbox escape on Node.js 26 via a stale PromiseThenLookupChain protector. Security teams using vm2 to isolate untrusted code are being urged to review the advisory and assess exposure.

  7. 7
    Critical CVE-2026-102829 flaw reported in simple-gitโ—๐Ÿšจ CVE-2026-102829 โ€” CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enabMmastodonTechnologyCybersecurity02 d ago

    A critical vulnerability, CVE-2026-102829 with a CVSS score of 9.2, has been disclosed in simple-git, the widely used Node.js package for running Git commands from JavaScript. The flaw stems from the argv-parser package, where versions before 2.0.1 omit VISUAL from the GitEnvKeys in parseEnv, affecting how prepareEnv handles the environment. Developers are being urged to check their dependencies and update.

  8. 8
    Critical vulnerability CVE-2026-102828 found in simple-git libraryโ—๐Ÿšจ CVE-2026-102828 โ€” CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enabMmastodonTechnologyCybersecurity02 d ago

    A critical vulnerability, CVE-2026-102828 with a CVSS score of 9.2, has been disclosed in simple-git, a widely used Node.js library for running Git commands from JavaScript. Versions 3.15.0 through 4.0.1 are affected because the default blockUnsafeOperationsPlugin fails to classify certain trailer .cmd values, potentially allowing unsafe Git operations. Developers are being urged to check their dependency versions and update promptly.

Repos