search
Node.js
Trends
- 1Fastify vulnerability EUVD-2026-70998 rated 7.5 publishedโผ๐จ EUVD-2026-70998 ๐ Score: 7.5/10 (CVSS v3.1) ๐ฆ Product: fastify ๐ข Vendor: fastify ๐ Updated: 2026-09-30 ๐ fastify vulne
A new vulnerability, EUVD-2026-70998, has been recorded for Fastify, the popular Node.js web framework. The flaw, rated 7.5 out of 10 on CVSS v3.1, allows a header validation bypass caused by incomplete schema case normalization. The entry in the European vulnerability database was updated on 30 September 2026. Security teams using Fastify are expected to review the advisory and check whether their deployments are affected.
- 2Fastify vulnerability EUVD-2026-70989 scores 7.5โผ๐จ EUVD-2026-70989 ๐ Score: 7.5/10 (CVSS v3.1) ๐ฆ Product: fastify ๐ข Vendor: fastify ๐ Updated: 2026-09-30 ๐ fastify vulne
A medium-high severity vulnerability, EUVD-2026-70989, has been catalogued in Fastify, the popular Node.js web framework. Rated 7.5 under CVSS v3.1, the flaw allows request validation bypass when boolean false schemas are skipped, potentially letting malformed requests through unchecked. The advisory was updated on 30 September 2026, and security teams using Fastify are being urged to review their validation logic and apply patches.
- 3Fastify vulnerability allows authentication bypass via malformed URLsโผ๐จ EUVD-2026-70988 ๐ Score: 7.5/10 (CVSS v3.1) ๐ฆ Product: fastify ๐ข Vendor: fastify ๐ Updated: 2026-09-30 ๐ fastify vulne
A newly catalogued vulnerability, EUVD-2026-70988, affects the Fastify web framework, rated 7.5 out of 10 on the CVSS v3.1 scale. The flaw allows authentication bypass when malformed URLs reach encapsulated not-found handlers, meaning requests intended to be blocked could slip through route protections. Fastify is a widely used Node.js framework, so developers running exposed services are being urged to review the advisory and update to a patched version.
- 4Graceful shutdown handlers fail when kill -9 strikesโYou write a graceful shutdown handler in Node.js, Python, or Go. You catch SIGTERM and SIGINT , close your database conn
Developers are discussing a common gap in software reliability: applications written in Node.js, Python, or Go often include shutdown handlers that catch SIGTERM and SIGINT, close database connections, flush files, and exit cleanly. But these handlers never run when a process receives SIGINT's harsher cousin, kill -9, or when Kubernetes force-kills a container after a timeout, leaving cleanup unfinished and potentially corrupting state.
- 5Critical 10/10 vulnerability flagged in vm2 sandbox libraryโ๐จ EUVD-2026-81591 ๐ Score: 10.0/10 (CVSS v3.1) ๐ฆ Product: vm2 ๐ข Vendor: patriksimek ๐ Updated: 2026-10-01 ๐ vm2 NodeVM c
A maximum-severity security flaw, tracked as EUVD-2026-81591, has been disclosed in vm2, the Node.js sandbox library maintained by Patrik Simek. The vulnerability, rated 10.0 out of 10 under CVSS v3.1, allows the NodeVM component to replace the host process TLS trust store, potentially undermining certificate validation. The advisory was updated on 1 October 2026 and appears in the EU vulnerability database.
- 6Critical vm2 sandbox escape vulnerability flagged in Node.jsโ๐จ EUVD-2026-81593 ๐ Score: 9.3/10 (CVSS v3.1) ๐ฆ Product: vm2 ๐ข Vendor: patriksimek ๐ Updated: 2026-10-01 ๐ vm2 sandbox e
A high-severity vulnerability, EUVD-2026-81593, has been catalogued affecting vm2, the JavaScript sandbox library maintained by Patrik Simek. The flaw scores 9.3 out of 10 on CVSS v3.1 and allows a sandbox escape on Node.js 26 via a stale PromiseThenLookupChain protector. Security teams using vm2 to isolate untrusted code are being urged to review the advisory and assess exposure.
- 7Critical CVE-2026-102829 flaw reported in simple-gitโ๐จ CVE-2026-102829 โ CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enab
A critical vulnerability, CVE-2026-102829 with a CVSS score of 9.2, has been disclosed in simple-git, the widely used Node.js package for running Git commands from JavaScript. The flaw stems from the argv-parser package, where versions before 2.0.1 omit VISUAL from the GitEnvKeys in parseEnv, affecting how prepareEnv handles the environment. Developers are being urged to check their dependencies and update.
- 8Critical vulnerability CVE-2026-102828 found in simple-git libraryโ๐จ CVE-2026-102828 โ CVSS 9.2 CRITICAL simple-git, an interface for running git commands in any node.js application, enab
A critical vulnerability, CVE-2026-102828 with a CVSS score of 9.2, has been disclosed in simple-git, a widely used Node.js library for running Git commands from JavaScript. Versions 3.15.0 through 4.0.1 are affected because the default blockUnsafeOperationsPlugin fails to classify certain trailer .cmd values, potentially allowing unsafe Git operations. Developers are being urged to check their dependency versions and update promptly.
Repos
- paperclipai/paperclip The open-source app everyone uses to manage agents at work
- dream-num/univer The Office Harness for AI Agents โ Spreadsheets, Docs, Slides, Canvas, Relational Tables, and PDF in one runtime.
- receptron/laya Run Laya, the open-source Jev-compatible System-1 decision model, from Node.js / TypeScript via ONNX Runtime