Known vulnerabilities in node-exporter

Software: node-exporter
Software CPE: cpe:2.3:o:fedoraproject:node-exporter:*:*:*:*:*:fedora:*:*
Total vulnerabilities: 14
Public exploits: 1
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting node-exporter node-exporter is affected by 14 known vulnerabilities: 10 medium, 4 low Critical High Medium Low

Vulnerabilities (14)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140620 - Resource exhaustion
CVE-2026-27145
CWE-400 Medium
No
No
1.12.0-1.el9, 1.12.0-1.el10_2, 1.12.0-1.el10_3, 1.12.0-1.fc43, 1.12.0-1.fc44, 1.12.1-1.el9, 1.12.1-1.el10_2, 1.12.1-1.fc43, 1.12.1-1.fc44 31.07.2026 SB2026073127
SB2026073129
SB2026073130
and 45 more
#VU118189 - Improper input validation
CVE-2025-58188
CWE-20 Medium
No
No
1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42, 1.10.2-3.fc44 07.11.2025 SB2025110705
SB2025110716
SB2025110717
and 113 more
#VU118187 - Resource exhaustion
CVE-2025-58185
CWE-400 Medium
No
No
1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42, 1.10.2-3.fc44 07.11.2025 SB2025110705
SB2025110716
SB2025110717
and 115 more
#VU118184 - Resource exhaustion
CVE-2025-61723
CWE-400 Medium
No
No
1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42, 1.10.2-3.fc44 07.11.2025 SB2025110705
SB2025110716
SB2025110717
and 121 more
#VU118183 - Improper Encoding or Escaping of Output
CVE-2025-58189
CWE-116 Low
No
No
1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42, 1.10.2-3.fc44 07.11.2025 SB2025110705
SB2025110711
SB2025110712
and 123 more
#VU118105 - UNIX Symbolic Link (Symlink) Following
CVE-2025-52881
CWE-61 Low
No
No
1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42, 1.10.2-3.fc43 05.11.2025 SB2025110519
SB2025110530
SB2025110545
and 62 more
#VU116686 - Protection Mechanism Failure
CVE-2025-47910
CWE-693 Medium
No
No
1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42 07.10.2025 SB2025100755
SB2025100756
SB2025100757
and 88 more
#VU114079 - Improper input validation
CVE-2025-47906
CWE-20 Low
No
No
1.10.2-3.el9, 1.10.2-3.el10_1, 1.10.2-3.el10_2, 1.10.2-3.fc42 14.08.2025 SB2025081423
SB2025081424
SB2025081425
and 130 more
#VU106253 - Improper input validation
CVE-2025-22870
CWE-20 Medium
Available
No
1.9.1-1.fc43, 1.9.1-2.el9 30.03.2025 SB2025033001
SB2025033002
SB2025033003
and 106 more
#VU82064 - Resource exhaustion
CVE-2023-39325
CWE-400 Medium
No
No
1.9.1-2.el9 16.10.2023 SB2023101651
SB2023101652
SB2023101653
and 341 more
#VU72686 - Resource exhaustion
CVE-2022-41723
CWE-400 Medium
No
No
1.9.1-2.el9 01.03.2023 SB2023030130
SB2023030131
SB2023030946
and 190 more
#VU70334 - Allocation of Resources Without Limits or Throttling
CVE-2022-41717
CWE-770 Medium
Available
No
1.9.1-2.el9 14.12.2022 SB2022121432
SB2022121433
SB2022121435
and 185 more
#VU69691 - Use of Password Hash Instead of Password for Authentication
CVE-2022-46146
CWE-836 Low
No
No
1.9.1-2.el9 29.11.2022 SB2022112926
SB2022113012
SB2023022044
and 33 more
#VU61599 - Improper input validation
CVE-2022-21698
CWE-20 Medium
No
No
1.9.1-2.el9 24.03.2022 SB2022021530
SB2022032413
SB2022040807
and 110 more