Known vulnerabilities in node-exporter
Vendor:
Fedoraproject
Software:
node-exporter
Software CPE:
cpe:2.3:o:fedoraproject:node-exporter:*:*:*:*:*:fedora:*:*
Website:
https://getfedora.org/
Total vulnerabilities:
14
Public exploits:
1
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (14)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU140620 - Resource exhaustion CVE-2026-27145 |
CWE-400 | Medium | 1.12.0-1.el9, 1.12.0-1.el10_2, 1.12.0-1.el10_3, 1.12.0-1.fc43, 1.12.0-1.fc44, 1.12.1-1.el9, 1.12.1-1.el10_2, 1.12.1-1.fc43, 1.12.1-1.fc44 | 31.07.2026 |
SB2026073127 SB2026073129 SB2026073130 and 45 more |
||
| #VU118189 - Improper input validation CVE-2025-58188 |
CWE-20 | Medium | 1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42, 1.10.2-3.fc44 | 07.11.2025 |
SB2025110705 SB2025110716 SB2025110717 and 113 more |
||
| #VU118187 - Resource exhaustion CVE-2025-58185 |
CWE-400 | Medium | 1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42, 1.10.2-3.fc44 | 07.11.2025 |
SB2025110705 SB2025110716 SB2025110717 and 115 more |
||
| #VU118184 - Resource exhaustion CVE-2025-61723 |
CWE-400 | Medium | 1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42, 1.10.2-3.fc44 | 07.11.2025 |
SB2025110705 SB2025110716 SB2025110717 and 121 more |
||
| #VU118183 - Improper Encoding or Escaping of Output CVE-2025-58189 |
CWE-116 | Low | 1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42, 1.10.2-3.fc44 | 07.11.2025 |
SB2025110705 SB2025110711 SB2025110712 and 123 more |
||
| #VU118105 - UNIX Symbolic Link (Symlink) Following CVE-2025-52881 |
CWE-61 | Low | 1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42, 1.10.2-3.fc43 | 05.11.2025 |
SB2025110519 SB2025110530 SB2025110545 and 62 more |
||
| #VU116686 - Protection Mechanism Failure CVE-2025-47910 |
CWE-693 | Medium | 1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42 | 07.10.2025 |
SB2025100755 SB2025100756 SB2025100757 and 88 more |
||
| #VU114079 - Improper input validation CVE-2025-47906 |
CWE-20 | Low | 1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42 | 14.08.2025 |
SB2025081423 SB2025081424 SB2025081425 and 130 more |
||
| #VU106253 - Improper input validation CVE-2025-22870 |
CWE-20 | Medium | 1.9.1-1.fc43, 1.9.1-2.el9 | 30.03.2025 |
SB2025033001 SB2025033002 SB2025033003 and 106 more |
||
| #VU82064 - Resource exhaustion CVE-2023-39325 |
CWE-400 | Medium | 1.9.1-2.el9 | 16.10.2023 |
SB2023101651 SB2023101652 SB2023101653 and 341 more |
||
| #VU72686 - Resource exhaustion CVE-2022-41723 |
CWE-400 | Medium | 1.9.1-2.el9 | 01.03.2023 |
SB2023030130 SB2023030131 SB2023030946 and 190 more |
||
| #VU70334 - Allocation of Resources Without Limits or Throttling CVE-2022-41717 |
CWE-770 | Medium | 1.9.1-2.el9 | 14.12.2022 |
SB2022121432 SB2022121433 SB2022121435 and 185 more |
||
| #VU69691 - Use of Password Hash Instead of Password for Authentication CVE-2022-46146 |
CWE-836 | Low | 1.9.1-2.el9 | 29.11.2022 |
SB2022112926 SB2022113012 SB2023022044 and 33 more |
||
| #VU61599 - Improper input validation CVE-2022-21698 |
CWE-20 | Medium | 1.9.1-2.el9 | 24.03.2022 |
SB2022021530 SB2022032413 SB2022040807 and 110 more |