n
node-fetch project
Security Risk Profile
43
/100
mediumSecurity Risk Score
Comprehensive risk assessment based on 3 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from September 10, 2020 to present
3
Total CVEs
1
Critical+High
0
Exploited
0
Unpatched
Threat Assessment
Avg CVSS
6.5
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
0
Critical/High
Risk Level
43/100
medium
Severity Distribution
Critical
0High
1Medium
2Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
Infoleak
1
2
Input Validation
1
Most Affected Products
1. Node-fetch Project Node-fetch Node.js9
2. npm/node-fetch4
3. Siemens Sinec Ins3
4. redhat/node-fetch2
5. redhat/rh-nodejs14-nodejs1
Recent Vulnerabilities
See more →CVE-2022-2596
CVSS 5.9medium
Inefficient Regular Expression Complexity in node-fetch/node-fetch
Aug 1, 2022
CVE-2022-0235
CVSS 6.1medium
Exposure of Sensitive Information to an Unauthorized Actor in node-fetch/node-fetch
Jan 14, 2022
CVE-2020-15168
CVSS 7.5high
File size limit bypass in node-fetch
Sep 10, 2020
Monitor node-fetch project in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.