Known vulnerabilities in npm24
Vendor:
SUSE
Software:
npm24
Software CPE:
cpe:2.3:o:suse:npm24:*:*:*:*:*:suse_linux:*:*
Website:
https://www.suse.com/
Total vulnerabilities:
36
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (36)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU146518 - Improper input validation CVE-2026-54272 |
CWE-20 | Medium | 24.18.1-150700.15.16.1 | 31.08.2026 |
SB20260831108 SB20260831126 SB20260831127 and 2 more |
||
| #VU140038 - Resource exhaustion CVE-2026-56846 |
CWE-400 | Medium | 24.18.1-150700.15.16.1 | 29.07.2026 |
SB2026072975 SB2026083143 SB2026083144 and 6 more |
||
| #VU140039 - Use After Free CVE-2026-56848 |
CWE-416 | Medium | 24.18.1-150700.15.16.1 | 29.07.2026 |
SB2026072975 SB2026083143 SB2026083144 and 6 more |
||
| #VU140040 - Improper Access Control CVE-2026-58043 |
CWE-284 | Low | 24.18.1-150700.15.16.1 | 29.07.2026 |
SB2026072975 SB2026083143 SB2026083144 and 6 more |
||
| #VU140041 - Authentication Bypass by Primary Weakness CVE-2026-56850 |
CWE-305 | Low | 24.18.1-150700.15.16.1 | 29.07.2026 |
SB2026072975 SB20260831126 SB20260831127 and 1 more |
||
| #VU140042 - Improper Certificate Validation CVE-2026-58040 |
CWE-295 | Medium | 24.18.1-150700.15.16.1 | 29.07.2026 |
SB2026072975 SB20260831126 SB20260831127 and 1 more |
||
| #VU140043 - Improper control of a resource through its lifetime CVE-2026-58041 |
CWE-664 | Low | 24.18.1-150700.15.16.1 | 29.07.2026 |
SB2026072975 SB20260831126 |
||
| #VU140044 - Improper input validation CVE-2026-58042 |
CWE-20 | Medium | 24.18.1-150700.15.16.1 | 29.07.2026 |
SB2026072975 SB20260831126 SB20260831127 and 1 more |
||
| #VU140045 - Improper input validation CVE-2026-58045 |
CWE-20 | Low | 24.18.1-150700.15.16.1 | 29.07.2026 |
SB2026072975 SB20260831126 SB20260831127 and 1 more |
||
| #VU140046 - Improper Access Control CVE-2026-56847 |
CWE-284 | Low | 24.18.1-150700.15.16.1 | 29.07.2026 |
SB2026072975 SB20260831126 SB20260831127 and 1 more |
||
| #VU140047 - Improper Access Control CVE-2026-58039 |
CWE-284 | Low | 24.18.1-150700.15.16.1 | 29.07.2026 |
SB2026072975 SB20260831126 SB20260831127 and 1 more |
||
| #VU140048 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling') CVE-2026-58044 |
CWE-444 | Medium | 24.18.1-150700.15.16.1 | 29.07.2026 |
SB2026072975 SB20260831126 SB20260831127 and 1 more |
||
| #VU134271 - Improper input validation CVE-2026-34182 |
CWE-20 | High | 24.18.1-150700.15.18.1 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610122 and 23 more |
||
| #VU134274 - NULL Pointer Dereference CVE-2026-42764 |
CWE-476 | Medium | 24.18.1-150700.15.18.1 | 10.06.2026 |
SB20260610118 SB20260610119 SB20260610123 and 13 more |
||
| #VU125567 - NULL Pointer Dereference CVE-2026-28390 |
CWE-476 | Medium | 24.18.1-150700.15.18.1 | 09.04.2026 |
SB2026040943 SB2026040944 SB2026040992 and 50 more |
||
| #VU125561 - Always-Incorrect Control Flow Implementation CVE-2026-2673 |
CWE-670 | Low | 24.18.1-150700.15.18.1 | 09.04.2026 |
SB2026040943 SB2026040944 SB20260409112 and 5 more |
||
| #VU122079 - Resource exhaustion CVE-2025-66199 |
CWE-400 | Medium | 24.18.1-150700.15.18.1 | 27.01.2026 |
SB2026012785 SB2026012791 SB2026012792 and 18 more |
||
| #VU116215 - Out-of-bounds read CVE-2025-9232 |
CWE-125 | Medium | 24.18.1-150700.15.18.1 | 01.10.2025 |
SB2025100119 SB2025100139 SB2025100153 and 13 more |
||
| #VU116214 - Covert Timing Channel CVE-2025-9231 |
CWE-385 | Low | 24.18.1-150700.15.18.1 | 01.10.2025 |
SB2025100119 SB2025100139 SB2025100153 and 10 more |
||
| #VU103771 - Improper Authentication CVE-2024-12797 |
CWE-287 | Medium | 24.18.1-150700.15.18.1 | 11.02.2025 |
SB2025021187 SB20250211108 SB20250211159 and 60 more |
Showing elements 1 - 20 out of 36