Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-56848 is a high-severity use-after-free vulnerability in Node.js HTTP/2 handling. It occurs when the function nghttp2_session_mem_send() is called re-entrantly during the execution of nghttp2_session_mem_recv(), leading to a heap-use-after-free condition. This flaw affects specific Node.js versions 26.5.0, 24.18.0, and 22.23.1. The vulnerability does not impact confidentiality or integrity but can cause denial of service due to application crashes. There is no confirmed patch or official remediation available at this time. Join the discussion | CVE Database V5 | 08/04/2026, 15:57:24 UTC Added: 08/04/2026, 16:28:46 UTC |
A vulnerability in Node.js versions 22.23.1, 24.18.0, and 26.5.0 exists where the dns.resolveAny() function aborts the Node.js process if a DNS response contains more than 256 A records. This can be repeatedly triggered to cause a denial of service condition. The issue is classified as CWE-400, indicating uncontrolled resource consumption. The CVSS v3.0 score is 5.9, reflecting a medium severity impact primarily affecting availability. Join the discussion | CVE Database V5 | 08/04/2026, 00:49:58 UTC Added: 08/04/2026, 01:03:31 UTC |
CVE-2026-56846 is a high-severity vulnerability in Node.js HTTP/2 handling that allows remote attackers to exhaust memory by evading maxSessionMemory limits through retained header blocks. It affects Node.js versions 22.23.1 and 24.18.0. The flaw results in uncontrolled resource consumption leading to denial of service. No official patch or remediation guidance is currently provided by the vendor. Join the discussion | CVE Database V5 | 08/04/2026, 00:49:58 UTC Added: 08/04/2026, 01:03:31 UTC |
CVE-2026-58044 is a low severity vulnerability in Node.js HTTP client affecting supported release lines 22, 24, and 26. It involves HTTP request smuggling due to request desynchronization in forwarding proxies that rebuild outbound headers from visible IncomingMessage headers while reusing backend connections. The flaw allows certain headers, including Content-Length, to be omitted from userland header objects but still used internally for HTTP framing, potentially causing inconsistencies. Join the discussion | CVE Database V5 | 08/04/2026, 00:49:58 UTC Added: 08/04/2026, 01:03:31 UTC |
A vulnerability in Node.js allows a specially crafted spoofed TypedArray byteLength to trigger an assertion failure in synchronous node:zlib APIs, causing the process to crash. This affects all 11 synchronous zlib functions and can be exploited repeatedly to cause denial of service. The issue impacts Node.js versions 22.x, 24.x, and 26.x. No official patch or remediation guidance is currently confirmed. Join the discussion | CVE Database V5 | 08/04/2026, 00:49:58 UTC Added: 08/04/2026, 01:03:31 UTC |
CVE-2026-58039 is a vulnerability in Node.js affecting versions 22.x, 24.x, and 26.x. It involves improper access control in the Node.js permission model, allowing process.report to write or overwrite files outside the intended --allow-fs-write paths. This flaw can lead to confidentiality impacts or bypass of security boundaries under certain configurations. The vulnerability has a low severity rating with a CVSS score of 3.3. Join the discussion | CVE Database V5 | 07/31/2026, 00:18:49 UTC Added: 07/31/2026, 00:37:40 UTC |
0 CVE-2026-58040 is a vulnerability in Node.js versions 22.x, 24.x, and 26.x where the HTTPS Agent's TLS session reuse mechanism skips hostname verification across identity policies. This issue is an incomplete fix of a previous vulnerability (CVE-2026-48934). The vulnerability has a medium severity with a CVSS score of 6.3 and does not have any known exploits in the wild at this time. Join the discussion | CVE Database V5 | 07/30/2026, 06:02:49 UTC Added: 07/30/2026, 06:24:12 UTC |
0 A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. Join the discussion | CVE Database V5 | 06/26/2026, 01:14:36 UTC Added: 06/26/2026, 01:31:11 UTC |
A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**. Join the discussion | CVE Database V5 | 06/26/2026, 01:14:36 UTC Added: 06/26/2026, 01:31:11 UTC |
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. Join the discussion | CVE Database V5 | 06/26/2026, 01:14:36 UTC Added: 06/26/2026, 01:31:11 UTC |
Showing 1 to 10 of 27 results