Tag: NodeJS

  • Framework Release Watch No18

    Node.js 24.21.0 adds crypto and performance improvements

  • Vulnerability Watch No65

    undici Cache Bug Enables Cross-Origin Data Exposure • undici TLS Validation Bypass Hits BalancedPool • PowerJob Worker Unauthenticated RCE Exposes Servers • IBM ContextForge Session Leak Exposes Data • IBM ContextForge Bug Allows Credential Theft…

  • Topics Everyone Is Talking About No414

    Bun 1.4: Enhanced Compatibility and Leaner JavaScript Tooling • OpenPubkey SSH: Bringing Single Sign-On to SSH Authentication • Rust Supply Chain Attack Compromises Arrayref Releases • From Rust to Zig: A Systems Developers First Impressions • Aaron Swartz, Data Scraping, and Unequal Tech Accountability…

  • Vulnerability Watch No47

    Hard-Coded Credentials Expose LB-LINK X-PRO • SQL Injection Hits SourceCodester Timetabling System • Fastify Multipart Flaw Enables Persistent Disk Exhaustion • Fastify Multipart Bug Can Exhaust Disk and Event Loop • Fastify JWT Key Override Breaks Authorization Boundaries…

  • Framework Release Watch No12

    NestJS 11.2.0 adds HTTP QUERY and SSE signals

  • Framework Release Watch No5

    Node.js 26.6.0 Expands FFI and Test Runner APIs • Node.js 24.19.0 Advances Streams, Networking, and TLS

  • Vulnerability Watch No13

    Critical Joomla Easy Store SQL Injection Exposes Databases • Joomla Easy Store Flaw Reveals Other Customers Orders • Joomla Easy Store Payment Forgery Bug Enables Order Manipulation • Proxygen HTTP2 Bug Can Trigger Memory Exhaustion DoS • CyberPanel Backup IDOR Lets Users Access Other Tenants…

  • Vulnerability Watch No7

    Network-AI Backup Prune Arbitrary File Deletion • xrdp DoS Bug Enables CPU Exhaustion • Network-AI Sandbox Bypass Leads to Command Execution • Network-AI MCP Server Authentication Bypass • WhatsApp MCP Server Exposes Files and Messaging…

  • Vulnerability Watch No5

    fast-uri URL Parsing Flaw Can Bypass Host-Based Security Checks • SQL Injection Found in SourceCodester Class and Exam Timetabling System • Public SQL Injection Vulnerability Impacts SourceCodester Timetabling System • uproot Code Generation Bug Enables Arbitrary Python Execution • Fastify Reply Plugin Cache Collision Risks Cross-Upstream Access…

  • Vulnerability Watch No1

    JLine Telnet Server Heap Exhaustion Flaw Hits Java Apps • Windows RDP Privacy Leak Exposes Private Information • HAPI FHIR Regex Bug Can Trigger Healthcare Service Outages • Avo Rails Framework Authorization Bypass Enables Data Exposure • ViewComponent XSS Flaw Risks Unsafe Rails Output…