[CIVN-2026-0180] Multiple Vulnerabilities in Node.js

By Published On: April 13, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Node.js


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


Node.js versions prior to v20.20.2

Node.js versions prior to v22.22.2

Node.js versions prior to v24.14.1

Node.js versions prior to v25.8.2

Overview


Multiple vulnerabilities have been identified in Node.js that could be exploited by an attacker to bypass security controls, access sensitive information, or cause denial of service on the targeted system.


Target Audience:

All organizations and developers using Node.js.


Risk Assessment:

High risk of unauthorized access, security bypass, and service disruption.


Impact Assessment:

Potential for information disclosure, execution of unauthorized actions, or denial of service conditions affecting application availability.


Description


Node.js is an open-source, cross-platform JavaScript runtime environment used for building scalable network applications.


These vulnerabilities exist due to improper error handling, memory leak issues and other flaws in Node.js. An attacker could exploit these by sending specially crafted requests.


Successful exploitation of these vulnerabilities could enable bypass of security controls, unauthorized access to sensitive information, or cause denial of service conditions on the targeted system.


Solution


Apply appropriate security updates as mentioned in:

https://nodejs.org/en/blog/vulnerability/march-2026-security-releases



Vendor Information


Node.js 

https://nodejs.org/en


References


 

https://nodejs.org/en/blog/vulnerability/march-2026-security-releases


CVE Name

CVE-2026-21637

CVE-2026-20953

CVE-2026-21710

CVE-2026-21711

CVE-2026-21712

CVE-2026-21713

CVE-2026-21714

CVE-2026-21715

CVE-2026-21716

CVE-2026-21717




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmnc9M4ACgkQ3jCgcSdc

ys9pVw//eocw5nNxxw6CUPNNoZITZAUCc78CjzUHUQ94MJiZ5HFMm7/Xh9i5DzF0

IGLLgzbxaarJxRaKlUh2NeDb40PMTBsx+ljlHzxdetZTBE0PXG04fKBT1Jt7ZEon

B4MEOCTnc6aa+TPjoOxEJzHtOAJ7MNCQBAJFjHrn8Sv/R7xmU6EmbDMU+ss35Kfu

neX6t5k1j5oRoGj/l8/pGaDM1bhFtsIMIG//ho2mmAv2fN4O7+iNYwuhWRtTSkU+

VixUAdS49ht+VAFJw+4tHh3BcnP+IqwZtGptMu3Kda1/lgxpyyzXM+XOnqXTk+aZ

+FHAGlYedKrby2ZcARCI4tYx35MauZVxgoxbVqYXm4vFmKslqMqzCOGpyUjeIRoX

c0VZwgIh8YW042A6lrchaQd+J1JgmMbKA1+Hx+8az55WSXYw98K9MhLF3h0Ou9F5

tT3EJ5p9Xo18Ke1yXC2q6gNlDg0vCPLI4QMSgu/hyVMAVvOxMlIAHEGDZTQAVMHC

p0qSNuugKWxgW1psVHEHdIHnn42pMgZy8zDmtKmbjlWoI8XPtc8BHXxY4/HH253V

1sJHALvxoZQa0NRlSVSk8T/wKkLfDPVwD9VQETMMj1pSbJfYmcvCPhjbGQe/dpXx

rmr/akhrS//o7Y9yBFsFsiBA8JFNRSjw1wA64TGDUliIJ3TbXbs=

=u/EU

—–END PGP SIGNATURE—–

Share this article