Skip to content
Threat Feed

Vendor

OpenJS Foundation

5 briefs RSS
medium advisory

Denial of Service Vulnerability in Node.js

A vulnerability in Node.js allows a remote, unauthenticated attacker to trigger a Denial of Service condition, impacting the availability of applications running on the affected environment.

Node.js denial-of-service nodejs software-vulnerability
1t
high advisory

Path Traversal in webpack-dev-middleware (CVE-2026-76844)

An incomplete fix for CVE-2024-29180 in webpack-dev-middleware allows path traversal via crafted URL requests when publicPath lacks a trailing slash, potentially leading to arbitrary local file read.

webpack-dev-middleware
1t 2c
high advisory

Electron Sandboxed Iframe Popup Restriction Bypass

A vulnerability in Electron, identified as CVE-2026-70608, allows sandboxed iframes to bypass 'allow-popups' restrictions and open new windows via the OpenURL navigation path.

Electron +4 vulnerability remote-code-execution javascript
2t 1c
high advisory

Information Disclosure and Denial of Service in Undici Cache Interceptor

The undici library is susceptible to cache poisoning leading to information disclosure and application crashes due to improper handling of malformed Cache-Control directives in the cache interceptor.

undici +1 vulnerability npm nodejs webserver
1c
high threat

Suspicious Execution with NodeJS

This rule detects suspicious Node.js execution patterns on Windows systems, including user-writable runtimes, preload arguments, and inline eval, decode, or child-process usage, indicating potential malicious activity.

Elastic Defend +4 nodejs execution windows
3r 1t