
[CIVN-2026-0345] Multiple Vulnerabilities in Node.js
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Node.js
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: HIGH
Software Affected
Node.js 22.x prior to 22.23.0
Node.js 24.x prior to 24.17.0
Node.js 26.x prior to 26.3.1
Overview
Multiple vulnerabilities have been reported in Node.js, which could allow an attacker to cause denial-of-service conditions, bypass security controls, disclose sensitive information, and perform unauthorized actions on the targeted system.
Target Audience:
All end-user organizations and individuals using Node.js.
Risk Assessment:
High risk of denial-of-service, bypass security restrictions, sensitive information disclosure.
Impact Assessment:
Potential for denial-of-service, bypass security restrictions, sensitive information disclosure and/or compromise of system.
Description
Node.js is an open-source, cross-platform JavaScript runtime environment that enables developers to build scalable server-side and network applications using JavaScript.
Multiple vulnerabilities have been reported in Node.js due to improper input validation, integer overflow conditions, hostname normalization inconsistencies, TLS certificate verification flaws, HTTP/2 protocol handling weaknesses, information disclosure issues, race conditions, and insufficient enforcement of the Permission Model. An attacker could exploit these vulnerabilities to crash Node.js processes, bypass authentication and authorization mechanisms, leak sensitive credentials, exhaust system resources, circumvent security restrictions, or manipulate network communications on the targeted system.
Successful exploitation of these vulnerabilities could allow an attacker to execute unauthorized actions, gain access to protected resources, disclose sensitive information, cause denial-of-service conditions, or bypass intended security boundaries on the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://nodejs.org/en/blog/vulnerability/june-2026-security-releases
Vendor Information
Node.js
https://nodejs.org/
References
https://nodejs.org/en/blog/vulnerability/june-2026-security-releases
CVE Name
CVE-2026-48933
CVE-2026-48618
CVE-2026-48615
CVE-2026-48617
CVE-2026-48619
CVE-2026-48937
CVE-2026-48928
CVE-2026-48930
CVE-2026-48934
CVE-2026-48935
CVE-2026-48936
CVE-2026-48931
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpD0rQACgkQ3jCgcSdc
ys8cxQ/+IWva36sTDq6SsDcdP5DAbXzOazyy8Mfg4gRhj4tAlWoYDtCF7I7WQ0au
6YagV+rg2zrV4oEFkQkFYb1YcfXyWFgbqStBeDOfa/J1F/QiZgDXO8jUk/xQJzzv
e10gqCc9LpJwiApo4Vj/le5kFzeIJOwavLZRSfsUG9zsaGaCPaa1GLxA0U0ePqcF
AOY2+cuuQ618RisWNnGIp5qdeGU/QsMG1gn+oOdJlTz0CFQdYO/lBbaT33xUZlxR
AU9msCJz6/+tjc3inYKA7HC1e5XNLbYvxtWVqijlbWBG63m+RQTpKPdiOtg5BYlO
BMlq6eQgpVrc0rldSRAxgbul8HE7sGk6olUFzNULyyLsAYhv2EBhqipbodQlLHBA
nXDH5A/GwGvtJPZObGE9NzEtYDpS9HFQ/mwHfWhjkYg79H6LiyRKnIf+oWFkT3RQ
w3lkFyGvTKMXyNR9w8trI7VsE8zsFW4AuUifwz7Ylq7HSEIuFRIwSRrQz6VQQV26
fql9dvCFfw1G2PPPvjcb1IQpoW3Rt0/uUUZv1lQD1cEv/Fn9nEiAWWAW1vAvvCyF
6lxgpHoHsJlucw3Z02RcYT2nyWN9X+Bi6XfkhUIkokzItCcHbg130HjYqdkUe+GM
bCZM0mVjMi/aTUKuC98vwoBSuBmJjWdTLC2Q6oxrGOwTQxwCNMU=
=QOmA
—–END PGP SIGNATURE—–


