Known vulnerabilities in nodejs-nodemon (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:nodejs-nodemon_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 22
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting nodejs-nodemon (Red Hat package) nodejs-nodemon (Red Hat package) is affected by 22 known vulnerabilities: 1 high, 19 medium, 2 low Critical High Medium Low

Vulnerabilities (22)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140707 - Resource exhaustion
CVE-2026-69152
CWE-400 Medium
No
No
3.1.14-3.el10_2 01.08.2026 SB2026080125
SB2026081044
#VU135820 - Inefficient Algorithmic Complexity
CVE-2026-13149
CWE-407 Medium
No
No
3.1.14-2.el10_0, 3.1.14-2.el10_2 29.06.2026 SB20260629111
SB2026072843
SB2026072877
and 11 more
#VU72750 - Inefficient Algorithmic Complexity
CVE-2022-25881
CWE-407 Medium
No
No
2.0.20-3.el9_2 03.03.2023 SB2023030326
SB2023030328
SB2023031112
and 61 more
#VU72557 - Memory corruption
CVE-2022-4904
CWE-119 Low
No
No
2.0.20-3.el9_2 24.02.2023 SB2023022410
SB2023022502
SB2023030233
and 38 more
#VU72404 - Incorrect Regular Expression
CVE-2023-24807
CWE-185 Medium
No
No
2.0.20-3.el9_2 20.02.2023 SB2023022022
SB2023022020
SB2023030129
and 34 more
#VU72403 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2023-23936
CWE-113 Medium
No
No
2.0.20-3.el9_2 20.02.2023 SB2023022022
SB2023022020
SB2023030129
and 35 more
#VU72400 - Permissions, Privileges, and Access Controls
CVE-2023-23920
CWE-264 Low
No
No
2.0.20-3.el9_2 20.02.2023 SB2023022020
SB2023030129
SB2023030337
and 55 more
#VU72398 - Permissions, Privileges, and Access Controls
CVE-2023-23918
CWE-264 Medium
No
No
2.0.20-3.el9_2 20.02.2023 SB2023022020
SB2023030129
SB2023030337
and 48 more
#VU69942 - Incorrect Regular Expression
CVE-2022-3517
CWE-185 Medium
No
No
2.0.20-2.el9_1 06.12.2022 SB2022120638
SB2022120639
SB2022120640
and 48 more
#VU69354 - Reliance on Reverse DNS Resolution for a Security-Critical Action
CVE-2022-43548
CWE-350 Medium
No
No
2.0.20-2.el9_1 15.11.2022 SB2022111599
SB20221115101
SB20221115102
and 47 more
#VU67850 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-35256
CWE-444 Medium
No
No
2.0.20-2.el9_1 03.10.2022 SB2022100347
SB2022100401
SB2022100402
and 50 more
#VU66955 - Improper Control of Generation of Code ('Code Injection')
CVE-2020-7788
CWE-94 Medium
No
No
2.0.19-1.el9_0 05.09.2022 SB2020121120
SB2022090501
SB2022091209
and 21 more
#VU66698 - Exposure of sensitive information to an unauthorized actor
CVE-2022-29244
CWE-200 Medium
No
No
2.0.19-1.el9_0 22.08.2022 SB2022082252
SB2022082253
SB2022091110
and 15 more
#VU65278 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-32214
CWE-444 Medium
No
No
2.0.19-1.el9_0 13.07.2022 SB2022071338
SB2022071610
SB2022071611
and 36 more
#VU65275 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2022-32213
CWE-444 Medium
No
No
2.0.19-1.el9_0 13.07.2022 SB2022071338
SB2022071610
SB2022071611
and 55 more
#VU65273 - Improper Check or Handling of Exceptional Conditions
CVE-2022-32212
CWE-703 Medium
No
No
2.0.19-1.el9_0 13.07.2022 SB2022071338
SB2022071610
SB2022071611
and 48 more
#VU64030 - Resource exhaustion
CVE-2021-44906
CWE-400 High
No
No
2.0.20-2.el9_1 07.06.2022 SB2022060836
SB2022062103
SB2022062203
and 52 more
#VU63698 - Incorrect Regular Expression
CVE-2021-33502
CWE-185 Medium
No
No
2.0.19-1.el9_0 26.05.2022 SB2021052416
SB2022052615
SB2022060618
and 17 more
#VU57967 - Improper input validation
CVE-2021-3807
CWE-20 Medium
No
No
2.0.19-1.el9_0 05.11.2021 SB2021110513
SB2021112603
SB2022042257
and 51 more
#VU52985 - Incorrect Regular Expression
CVE-2020-28469
CWE-185 Medium
No
No
2.0.19-1.el9_0 10.05.2021 SB2021051002
SB2021051004
SB2021072625
and 26 more


Showing elements 1 - 20 out of 22