node-fetch project records
3 published records for vendor node-fetch project.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-1333 Inefficient Regular Expression Complexity1
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
3 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
24Monitor | CVE-2022-0235No exploit | Exposure of Sensitive Information to an Unauthorized Actor in node-fetch/node-fetchnode-fetch project · node-fetch · CWE-200 | Medium6.1 | — | 1.7% | Jan 16, 2022 |
23Monitor | CVE-2022-2596No exploit | Inefficient Regular Expression Complexity in node-fetch/node-fetchnode-fetch project · node-fetch · CWE-1333 | Medium5.9 | — | 1.3% | Aug 1, 2022 |
22Monitor | CVE-2020-15168No exploit | File size limit bypass in node-fetchnode-fetch project · node-fetch · CWE-20 | Medium5.3 | — | 1.7% | Sep 10, 2020 |
- CVE-2022-023524Monitor
Exposure of Sensitive Information to an Unauthorized Actor in node-fetch/node-fetch
MediumCVSS 6.1No exploitEPSS 2%node-fetch project · node-fetchJan 16, 2022
- CVE-2022-259623Monitor
Inefficient Regular Expression Complexity in node-fetch/node-fetch
MediumCVSS 5.9No exploitEPSS 1%node-fetch project · node-fetchAug 1, 2022
- CVE-2020-1516822Monitor
File size limit bypass in node-fetch
MediumCVSS 5.3No exploitEPSS 2%node-fetch project · node-fetchSep 10, 2020