Skip to main content

Vendor/product archive

nestjs / nest CVEs

Beta · best-effort

7 CVEs tagged to nestjs / nest0 Critical, 3 High, 3 Medium, 1 Low, 0 Unrated.

CVE-2026-40879

Published Apr 21, 2026

Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.19, when an attacker sends many small, valid JSON messages in one TCP frame, handleData()…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-35515

Published Apr 7, 2026

Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.18, SseStream._transform() interpolates message.type and message.id directly into Server-…

CVSS 6.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-33011

Published Mar 20, 2026

Nest is a framework for building scalable Node.js server-side applications. In versions 11.1.15 and below, a NestJS application using @nestjs/platform-fastify GET middleware can b…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-2293

Published Feb 27, 2026

A NestJS application using @nestjs/platform-fastify can allow bypass of authentication/authorization middleware when Fastify path-normalization options are enabled. This issue…

CVSS 8.2 · High
evidence mentions
6
Buzz score
34.0
Vendor/product tagsBeta · best-effort

CVE-2025-69211

Published Dec 29, 2025

Nest is a framework for building scalable Node.js server-side applications. Versions prior to 11.1.11 have a Fastify URL encoding middleware bypass. A NestJS application is vulner…

CVSS 6.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-29409

Published Mar 14, 2025

File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26108

Published Mar 6, 2023

Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe. Exploiting this vulnerability is possible when the client can…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1