VendorsFeathersjsfeathersall versions
Vulnerabilities

Feathersjs Feathers

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-29792
Feathersjs has an OAuth Callback Account Takeover
Published 2026-03-10 · Analyzed
9.8EPSS 0.006
CVE-2026-29793
NoSQL Injection via WebSocket id Parameter in MongoDB Adapter
Published 2026-03-10 · Analyzed
9.8EPSS 0.006
CVE-2026-27193
Feathers exposes internal headers via unencrypted session cookie
Published 2026-02-21 · Analyzed
8.2EPSS 0.004
CVE-2026-27192
Feathers has an origin validation bypass via prefix matching
Published 2026-02-21 · Analyzed
8.1EPSS 0.003
CVE-2023-37899
feathersjs socket handler allows abusing implicit toString
Published 2023-07-19 · Modified
7.5EPSS 0.012
CVE-2026-27191
Feathers: Open Redirect in OAuth callback enables account takeover
Published 2026-02-21 · Analyzed
7.4EPSS 0.003