Node.js Multiple Vulnerabilities
Release Date: 30 Jul 2026
RISK: Medium Risk
TYPE: Servers - Other Servers
Multiple vulnerabilities have been identified in Node.js. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, security restriction bypass, sensitive information disclosure, remote code execution, data manipulation and spoofing on the targeted system.
Impact
- Denial of Service
- Elevation of Privilege
- Spoofing
- Remote Code Execution
- Information Disclosure
- Data Manipulation
- Security Restriction Bypass
System / Technologies affected
- Node.js versions prior to 22.23.2 (LTS)
- Node.js versions prior to 24.18.1 (LTS)
- Node.js versions prior to 26.5.1 (Current)
Solutions
Before installation of the software, please visit the vendor web-site for more details.
- Update to Node.js version 22.23.2 (LTS)
- Update to Node.js version 24.18.1 (LTS)
- Update to Node.js version 26.5.1 (Current)
Vulnerability Identifier
- CVE-2026-48934
- CVE-2026-56846
- CVE-2026-56847
- CVE-2026-56848
- CVE-2026-56850
- CVE-2026-58039
- CVE-2026-58040
- CVE-2026-58041
- CVE-2026-58042
- CVE-2026-58043
- CVE-2026-58044
- CVE-2026-58045
沒有留言:
發佈留言