2026年7月30日星期四

Node.js Multiple Vulnerabilities

Node.js Multiple Vulnerabilities

Release Date: 30 Jul 2026

RISK: Medium Risk

TYPE: Servers - Other Servers

Multiple vulnerabilities have been identified in Node.js. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, security restriction bypass, sensitive information disclosure, remote code execution, data manipulation and spoofing on the targeted system.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Spoofing
  • Remote Code Execution
  • Information Disclosure
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • Node.js versions prior to 22.23.2 (LTS)
  • Node.js versions prior to 24.18.1 (LTS)
  • Node.js versions prior to 26.5.1 (Current)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Update to Node.js version 22.23.2 (LTS)
  • Update to Node.js version 24.18.1 (LTS)
  • Update to Node.js version 26.5.1 (Current)

Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

Mozilla Firefox 多個漏洞

Mozilla Firefox 多個漏洞 發佈日期 : 2026 年 09 月 30 日 於 Mozilla Firefox 發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、繞過保安限制、敏感資料洩露、遠端執行任意程式碼及彷冒。 ...