[CIVN-2026-0345] Multiple Vulnerabilities in Node.js

By Published On: June 30, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Node.js


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: HIGH


Software Affected


Node.js 22.x prior to 22.23.0 

Node.js 24.x prior to 24.17.0

Node.js 26.x prior to 26.3.1

Overview


Multiple vulnerabilities have been reported in Node.js, which could allow an attacker to cause denial-of-service conditions, bypass security controls, disclose sensitive information, and perform unauthorized actions on the targeted system.


Target Audience:

All end-user organizations and individuals using Node.js.


Risk Assessment:

High risk of denial-of-service, bypass security restrictions, sensitive information disclosure.


Impact Assessment:

Potential for denial-of-service, bypass security restrictions, sensitive information disclosure and/or compromise of system.


Description


Node.js is an open-source, cross-platform JavaScript runtime environment that enables developers to build scalable server-side and network applications using JavaScript.


Multiple vulnerabilities have been reported in Node.js due to improper input validation, integer overflow conditions, hostname normalization inconsistencies, TLS certificate verification flaws, HTTP/2 protocol handling weaknesses, information disclosure issues, race conditions, and insufficient enforcement of the Permission Model. An attacker could exploit these vulnerabilities to crash Node.js processes, bypass authentication and authorization mechanisms, leak sensitive credentials, exhaust system resources, circumvent security restrictions, or manipulate network communications on the targeted system.


Successful exploitation of these vulnerabilities could allow an attacker to execute unauthorized actions, gain access to protected resources, disclose sensitive information, cause denial-of-service conditions, or bypass intended security boundaries on the targeted system.


Solution


Apply appropriate updates as mentioned by the vendor:

https://nodejs.org/en/blog/vulnerability/june-2026-security-releases



Vendor Information


Node.js

https://nodejs.org/


References


 

https://nodejs.org/en/blog/vulnerability/june-2026-security-releases


CVE Name

CVE-2026-48933

CVE-2026-48618

CVE-2026-48615

CVE-2026-48617

CVE-2026-48619

CVE-2026-48937

CVE-2026-48928

CVE-2026-48930

CVE-2026-48934

CVE-2026-48935

CVE-2026-48936

CVE-2026-48931




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpD0rQACgkQ3jCgcSdc

ys8cxQ/+IWva36sTDq6SsDcdP5DAbXzOazyy8Mfg4gRhj4tAlWoYDtCF7I7WQ0au

6YagV+rg2zrV4oEFkQkFYb1YcfXyWFgbqStBeDOfa/J1F/QiZgDXO8jUk/xQJzzv

e10gqCc9LpJwiApo4Vj/le5kFzeIJOwavLZRSfsUG9zsaGaCPaa1GLxA0U0ePqcF

AOY2+cuuQ618RisWNnGIp5qdeGU/QsMG1gn+oOdJlTz0CFQdYO/lBbaT33xUZlxR

AU9msCJz6/+tjc3inYKA7HC1e5XNLbYvxtWVqijlbWBG63m+RQTpKPdiOtg5BYlO

BMlq6eQgpVrc0rldSRAxgbul8HE7sGk6olUFzNULyyLsAYhv2EBhqipbodQlLHBA

nXDH5A/GwGvtJPZObGE9NzEtYDpS9HFQ/mwHfWhjkYg79H6LiyRKnIf+oWFkT3RQ

w3lkFyGvTKMXyNR9w8trI7VsE8zsFW4AuUifwz7Ylq7HSEIuFRIwSRrQz6VQQV26

fql9dvCFfw1G2PPPvjcb1IQpoW3Rt0/uUUZv1lQD1cEv/Fn9nEiAWWAW1vAvvCyF

6lxgpHoHsJlucw3Z02RcYT2nyWN9X+Bi6XfkhUIkokzItCcHbg130HjYqdkUe+GM

bCZM0mVjMi/aTUKuC98vwoBSuBmJjWdTLC2Q6oxrGOwTQxwCNMU=

=QOmA

—–END PGP SIGNATURE—–

Share this article