Known Vulnerabilities for Node-fetch by Node-fetch Project
Listed below are 3 of the newest known vulnerabilities associated with "Node-fetch" by "Node-fetch Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-103757 json | Budibase through 3.41.0 contains a server-side request forgery vulnerability in AI table generation because the uploadUrl fun... | Not Provided | 2026-10-01 | 2026-10-01 |
| CVE-2026-101908 json | Axios is a promise-based HTTP client for the browser and Node.js. From 1.7.0 until 1.20.0, the fetch adapter constructs a Req... | Not Provided | 2026-09-28 | 2026-09-28 |
| CVE-2026-101907 json | Axios is a promise-based HTTP client for the browser and Node.js. From 1.17.0 until 1.20.0, the fetch adapter bypasses the ma... | Not Provided | 2026-09-28 | 2026-09-28 |
| CVE-2026-101900 json | Axios is a promise-based HTTP client for the browser and Node.js. From 1.12.0 until 1.20.0, ResolveConfig reads inherited Sym... | Not Provided | 2026-09-28 | 2026-09-28 |
| CVE-2026-92587 json | n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative rem... | Not Provided | 2026-09-16 | 2026-09-21 |
| CVE-2026-89809 json | In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debu... | Not Provided | 2026-09-16 | 2026-09-17 |
| CVE-2026-86995 json | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the reposit... | Not Provided | 2026-09-08 | 2026-09-09 |
| CVE-2026-84301 json | FastGPT is an open-source LLM platform for building AI applications on a knowledge base. Prior to 4.15.2, the safe Axios requ... | Not Provided | 2026-09-22 | 2026-09-25 |
| CVE-2026-81633 json | Improper Input Validation vulnerability in ash-project ash_graphql allows an unauthenticated client to crash a relay node(id:... | Not Provided | 2026-08-30 | 2026-08-31 |
| CVE-2026-80762 json | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Fix accept list UAF during suspend ... | Not Provided | 2026-09-04 | 2026-09-04 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Node-fetch Project | Node-fetch | 3.0.0 | |||
| Application | Node-fetch Project | Node-fetch | 3.0.0 | |||
| Application | Node-fetch Project | Node-fetch | 3.0.0 | |||
| Application | Node-fetch Project | Node-fetch | 3.0.0 | |||
| Application | Node-fetch Project | Node-fetch | 3.0.0 | |||
| Application | Node-fetch Project | Node-fetch | 3.0.0 | |||
| Application | Node-fetch Project | Node-fetch | 2.6.1 | |||
| Application | Node-fetch Project | Node-fetch | 2.6.0 | |||
| Application | Node-fetch Project | Node-fetch | 2.5.0 | |||
| Application | Node-fetch Project | Node-fetch | 2.4.1 | |||
| Application | Node-fetch Project | Node-fetch | 2.4.0 | |||
| Application | Node-fetch Project | Node-fetch | 2.3.0 | |||
| Application | Node-fetch Project | Node-fetch | 2.2.1 | |||
| Application | Node-fetch Project | Node-fetch | 2.2.0 | |||
| Application | Node-fetch Project | Node-fetch | 2.1.2 | |||
| Application | Node-fetch Project | Node-fetch | 2.1.1 | |||
| Application | Node-fetch Project | Node-fetch | 2.1.0 | |||
| Application | Node-fetch Project | Node-fetch | 2.0.0 | |||
| Application | Node-fetch Project | Node-fetch | 2.0.0 | |||
| Application | Node-fetch Project | Node-fetch | 2.0.0 |