VendorsNestJSnestall versions
Vulnerabilities

NestJS Nest

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2026-2293
NestJS 11.1.13 - Lack of data validation allowing authentication/authorization bypass
Published 2026-02-27 · Modified
9.8EPSS 0.007
CVE-2026-33011
Nest Fastify HEAD Request Middleware Bypass
Published 2026-03-20 · Analyzed
8.7EPSS 0.005
CVE-2026-40879
Nest: DoS via Recursive handleData in JsonSocket (TCP Transport)
Published 2026-04-21 · Analyzed
7.5EPSS 0.005
CVE-2025-69211
Nest has a Fastify URL Encoding Middleware Bypass (TOCTOU)
Published 2025-12-29 · Analyzed
7.4EPSS 0.004
CVE-2026-35515
@nestjs/core Improperly Neutralizes Special Elements in Output Used by a Downstream Component ('Injection')
Published 2026-04-07 · Analyzed
6.3EPSS 0.003
CVE-2024-29409
File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.
Published 2025-03-14 · Analyzed
5.5EPSS 0.003
CVE-2023-26108
Versions of the package @nestjs/core before 9.0.5 are vulnerable to Information Exposure via the StreamableFile pipe. Exploiting this vulnerability is possible when the client cancels a request while it is streaming a StreamableFile, the stream wrapped by the StreamableFile will be kept open.
Published 2023-03-06 · Modified
5.3EPSS 0.007