NestJS API Security Remediation
OWASP API Top 10 remediation guides for TypeScript developers.
-
Broken Authentication
Broken Authentication in NestJS: Fix [CVE-2022-31069]
CVE -
Broken Authentication
Broken Authentication in NestJS Proxy [Month Year] [CVE-2022-31070]
CVE -
Broken Authentication
Broken Authentication in NestJS CVE-2024-29409 [CVE-2024-29409]
CVE -
Broken Function Level Authorization
Broken Function Level Authorization in NestJS [Mar 2026] [CVE-2022-31069]
CVE -
Broken Function Level Authorization
Broken Function Level Authorization - NestJS [Updated 2026-03] [CVE-2022-31070]
CVE -
Broken Function Level Authorization
Broken Function Level Authorization in NestJS [Mar 2026] [CVE-2024-29409]
CVE -
Broken Object Level Authorization
Broken Object Level Authorization in NestJS [Mar 2026] [CVE-2026-2293]
CVE -
Broken Object Property Level Authorization
Broken Object Property Level Authorization in NestJS Proxy [CVE-2022-31069]
CVE -
Broken Object Property Level Authorization
Broken Object Property Level Authorization in NestJS [CVE-2022-31070]
CVE -
Broken Object Property Level Authorization
Broken Object Property Level Authorization NestJS naturally [CVE-2026-2293]
CVE -
Injection
NestJS Injection: CVE-2022-31069 (Proxy) [Month Year] [CVE-2022-31069]
CVE -
Injection
Injection in NestJS: Cookie Forwarding (CVE-2022-31070) [CVE-2022-31070]
CVE -
Injection
NestJS Injection Remediation Guide [Mar 2026] [CVE-2024-29409]
CVE -
Security Misconfiguration
Security Misconfiguration in NestJS - Token Forwarding [CVE-2022-31069]
CVE -
Security Misconfiguration
Security Misconfiguration and NestJS [CVE-2022-31070]
CVE -
Security Misconfiguration
Security Misconfiguration in NestJS: File Upload RCE [CVE-2024-29409]
CVE -
Sensitive Data Exposure
Sensitive Data Exposure and NestJS CVE-2022-31069 [CVE-2022-31069]
CVE -
Sensitive Data Exposure
Sensitive Data Exposure in NestJS Proxy (CVE-2022-31070) [CVE-2022-31070]
CVE -
SSRF
SSRF in NestJS Proxy: Fix Unauthorized Token Forwarding [CVE-2022-31069]
CVE -
SSRF
NestJS SSRF Cookie Block (CVE-2022-31070) [CVE-2022-31070]
CVE -
SSRF
SSRF in NestJS: CVE-2024-29409 fix [June 2026] [CVE-2024-29409]
CVE -
SSRF
SSRF in NestJS: Secure External Fetches [March 2026] [GHSA-89v5-38xr-9m4j]
CVE -
Unrestricted Resource Consumption
Unrestricted Resource Consumption in NestJS Token Forwarding [CVE-2022-31069]
CVE -
Unrestricted Resource Consumption
Unrestricted Resource Consumption in NestJS - Proxy Cookie [CVE-2022-31070]
CVE -
Unrestricted Resource Consumption
Unrestricted Resource Consumption in NestJS [CVE-2024-29409]
CVE
>_ Scan your TypeScript API
Detect these vulnerabilities automatically
ApiPosture scans your API codebase and flags OWASP issues before they reach production.