References https://www.tenablecloud.cn/plugins/nessus/165634 https://avd.aliyun.com/detail?id=AVD-2023-30589 https://github.com/advisories/GHSA-cggh-pq45-6h9x https://nvd.nist.gov/vuln/detail/cve-2023-30589 https://security.snyk.io/vuln/SNYK-UPSTREAM-NODE-5741793 https://www.sentinelone.com/vulnerability-database/cve-2023-30589/ https://www.herodevs.com/vulnerability-directory/cve-2023-30589 https://access.redhat.com/security/cve/CVE-2023-30589 https://zeropath.com/blog/cve-2022-35256-nodejs-http-request-smuggling https://nvd.nist.gov/vuln/detail/cve-2022-35256 https://nodejs.org/en/blog/vulnerability/september-2022-security-releases https://www.sentinelone.com/vulnerability-database/cve-2022-35256/ https://cloud.tencent.com/developer/article/2562956 https://hackerone.com/reports/2001873 https://www.venustech.com.cn/new_type/aqtg/20220713/24167.html https://app.opencve.io/cve/?vendor=llhttp https://github.com/nodejs/llhttp/security https://llhttp.org/ https://www.miggo.io/vulnerability-database/cve/CVE-2022-32213 https://nvd.nist.gov/vuln/detail/cve-2025-23167 https://www.tenablecloud.cn/plugins/nessus/165634
Related VulnerabilitiesPoCCVE-2026-46442: Flowise < 3.1.2 - node-custom-function Unauthorized RCEFlowiseAI Flowise /api/v1/node-custom-function 代码执行漏洞(CVE-2026-46442)Drupal core /jsonapi/node/article SQL 注入漏洞(CVE-2026-9082)Apache HTTP/2 双重释放漏洞(CVE-2026-23918)PoCspringboot-httpexchanges: Detects Springboot HTTP Exchanges ActuatorPoCNode-RED /auth/token 默认口令漏洞Vite Dev Server /node_modules/.vite/deps 文件读取漏洞 (CVE-2026-39365)PoCCVE-2025-64500: Symfony HttpFoundation - Access Control Bypass via PATH_INFOPoCnode-red-unauth: Node-RED - Unauthenticated AccessNocoBase /api/flow_nodes:test 代码执行漏洞(CVE-2026-34156)天锐绿盘云文档安全管理平台/lddsm/service/../ldfbsnodeDocumentController/restorMachineToClient.do 命令执行漏洞Node-Tar Node-Tar 未授权 路径遍历漏洞ComfyUI /api/customnode/install/git_url 代码执行漏洞(CVE-2025-67303)