
[CIVN-2026-0180] Multiple Vulnerabilities in Node.js
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Node.js
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Node.js versions prior to v20.20.2
Node.js versions prior to v22.22.2
Node.js versions prior to v24.14.1
Node.js versions prior to v25.8.2
Overview
Multiple vulnerabilities have been identified in Node.js that could be exploited by an attacker to bypass security controls, access sensitive information, or cause denial of service on the targeted system.
Target Audience:
All organizations and developers using Node.js.
Risk Assessment:
High risk of unauthorized access, security bypass, and service disruption.
Impact Assessment:
Potential for information disclosure, execution of unauthorized actions, or denial of service conditions affecting application availability.
Description
Node.js is an open-source, cross-platform JavaScript runtime environment used for building scalable network applications.
These vulnerabilities exist due to improper error handling, memory leak issues and other flaws in Node.js. An attacker could exploit these by sending specially crafted requests.
Successful exploitation of these vulnerabilities could enable bypass of security controls, unauthorized access to sensitive information, or cause denial of service conditions on the targeted system.
Solution
Apply appropriate security updates as mentioned in:
https://nodejs.org/en/blog/vulnerability/march-2026-security-releases
Vendor Information
Node.js
https://nodejs.org/en
References
https://nodejs.org/en/blog/vulnerability/march-2026-security-releases
CVE Name
CVE-2026-21637
CVE-2026-20953
CVE-2026-21710
CVE-2026-21711
CVE-2026-21712
CVE-2026-21713
CVE-2026-21714
CVE-2026-21715
CVE-2026-21716
CVE-2026-21717
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmnc9M4ACgkQ3jCgcSdc
ys9pVw//eocw5nNxxw6CUPNNoZITZAUCc78CjzUHUQ94MJiZ5HFMm7/Xh9i5DzF0
IGLLgzbxaarJxRaKlUh2NeDb40PMTBsx+ljlHzxdetZTBE0PXG04fKBT1Jt7ZEon
B4MEOCTnc6aa+TPjoOxEJzHtOAJ7MNCQBAJFjHrn8Sv/R7xmU6EmbDMU+ss35Kfu
neX6t5k1j5oRoGj/l8/pGaDM1bhFtsIMIG//ho2mmAv2fN4O7+iNYwuhWRtTSkU+
VixUAdS49ht+VAFJw+4tHh3BcnP+IqwZtGptMu3Kda1/lgxpyyzXM+XOnqXTk+aZ
+FHAGlYedKrby2ZcARCI4tYx35MauZVxgoxbVqYXm4vFmKslqMqzCOGpyUjeIRoX
c0VZwgIh8YW042A6lrchaQd+J1JgmMbKA1+Hx+8az55WSXYw98K9MhLF3h0Ou9F5
tT3EJ5p9Xo18Ke1yXC2q6gNlDg0vCPLI4QMSgu/hyVMAVvOxMlIAHEGDZTQAVMHC
p0qSNuugKWxgW1psVHEHdIHnn42pMgZy8zDmtKmbjlWoI8XPtc8BHXxY4/HH253V
1sJHALvxoZQa0NRlSVSk8T/wKkLfDPVwD9VQETMMj1pSbJfYmcvCPhjbGQe/dpXx
rmr/akhrS//o7Y9yBFsFsiBA8JFNRSjw1wA64TGDUliIJ3TbXbs=
=u/EU
—–END PGP SIGNATURE—–


