o
openjs foundation
Security Risk Profile
30
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 62 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from January 20, 2015 to present
62
Total CVEs
2
Critical+High
0
Exploited
2
Unpatched
Threat Assessment
Avg CVSS
4.9
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
2
Critical/High
Risk Level
30/100
low
Severity Distribution
Critical
0High
2Medium
8Low
2Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
0Age Distribution
Common Weaknesses (CWE)
1
SQL Injection
1
2
Input Validation
1
Most Affected Products
1. OpenJS Foundation Node.js62
2. Nodejs Node.js15
3. Microsoft azl3 nodejs24 24.13.0-33
4. OpenJS Foundation Node.js 222
5. OpenJS Foundation Node.js 242
Recent Vulnerabilities
See more →CVE-2026-58041
CVSS 5.3medium
Aug 4, 2026🔧 No Patch
CVE-2026-58040
CVSS 6.3medium
Jul 30, 2026
REDHAT-BUG-2493332
CVSS 4.0medium
Jun 26, 2026🔧 No Patch
CVE-2026-48618
CVSS 7.7high
Jun 26, 2026🔧 No Patch
CVE-2026-48937
CVSS 7.5high
Jun 18, 2026🔧 No Patch
https://seclists.org/oss-sec/2026/q2/965
unknown
Fwd: Node.js security updates for all active lease lines, June 2026
Jun 18, 2026🔧 No Patch
https://seclists.org/oss-sec/2026/q2/872
unknown
Fwd: Node.js security updates for all active lease lines, June 2026
Jun 10, 2026🔧 No Patch
https://reddit.com/r/cybersecurity/comments/1t6dyji/critical_vm2_sandbox_escape_vulnerabilities/
unknown
Critical vm2 Sandbox Escape Vulnerabilities Expose Node.js Apps to Full Host RCE
May 7, 2026🔧 No Patch
EOL-nodejs-26
unknown
May 5, 2026
REDHAT-BUG-2453160
CVSS 4.0medium
Mar 30, 2026🔧 No Patch
Monitor openjs foundation in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.