expressjs 漏洞与 CVE 列表(5)

产品(CPE): — CVE 数: 5

expressjs 漏洞概览

汇总 expressjs 相关全部产品的 CVE 与安全漏洞情报,包括 CVSS、EPSS、公开时间与漏洞情报数据。

已披露问题常与 缓冲区溢出与拒绝服务 相关,可能在 软件部署与生产负载 场景中带来 应用崩溃 等暴露风险。

相关漏洞数据主要来源于公开漏洞披露与安全公告,可用于评估历史漏洞暴露面与修复优先级。

漏洞分布趋势(近 24 个月)

显示 155 CVE 数
«« 第一页 « 上一页 第 1 / 1 页 下一页 »
CVE 摘要 来源 最高 CVSS EPSS % 公开时间 更新时间
CVE-2026-3520 Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing stack overflow. Users should upgrade to version 2.1.1 to receive a patch. No known workarounds are available. ce714d77-add3-4f53-aff5-83d477b104bb 8.7 0.06% 2026-03-04 2026-03-09
CVE-2026-3304 Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available. ce714d77-add3-4f53-aff5-83d477b104bb 8.7 0.02% 2026-02-27 2026-03-19
CVE-2026-2359 Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.0 allows an attacker to trigger a Denial of Service (DoS) by dropping connection during file upload, potentially causing resource exhaustion. Users should upgrade to version 2.1.0 to receive a patch. No known workarounds are available. ce714d77-add3-4f53-aff5-83d477b104bb 8.7 0.02% 2026-02-27 2026-03-19
CVE-2024-47178 basic-auth-connect is Connect's Basic Auth middleware in its own module. basic-auth-connect < 1.1.0 uses a timing-unsafe equality comparison that can leak timing information. This issue has been fixed in basic-auth-connect 1.1.0. [email protected] 8.7 0.29% 2024-09-30 2024-11-15
CVE-2017-16136 method-override is a module used by the Express.js framework to let you use HTTP verbs such as PUT or DELETE in places where the client doesn't support it. method-override is vulnerable to a regular expression denial of service vulnerability when specially crafted input is passed in to be parsed via the X-HTTP-Method-Override header. [email protected] 7.5 0.33% 2018-06-07 2024-11-21
«« 第一页 « 上一页 第 1 / 1 页 下一页 »
cvelogic Threat Intelligence