CVE-2026-48935
- EPSS 0.19%
- Veröffentlicht 26.06.2026 01:14:36
- Zuletzt bearbeitet 26.06.2026 20:14:33
A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 2...
CVE-2026-48936
- EPSS 0.15%
- Veröffentlicht 26.06.2026 01:14:36
- Zuletzt bearbeitet 26.06.2026 19:55:59
A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.
CVE-2026-48931
- EPSS 0.35%
- Veröffentlicht 22.06.2026 18:59:30
- Zuletzt bearbeitet 03.07.2026 01:16:22
A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
CVE-2026-48937
- EPSS 0.57%
- Veröffentlicht 18.06.2026 18:01:39
- Zuletzt bearbeitet 18.08.2026 17:54:16
A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**.
CVE-2026-48617
- EPSS 0.32%
- Veröffentlicht 18.06.2026 16:21:12
- Zuletzt bearbeitet 19.08.2026 20:02:10
A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability ...
CVE-2026-21710
- EPSS 25.04%
- Veröffentlicht 30.03.2026 19:07:28
- Zuletzt bearbeitet 19.08.2026 14:32:04
A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototy...
CVE-2026-21711
- EPSS 0.15%
- Veröffentlicht 30.03.2026 19:07:28
- Zuletzt bearbeitet 19.08.2026 13:52:49
A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permissi...
CVE-2026-21713
- EPSS 0.39%
- Veröffentlicht 30.03.2026 19:07:28
- Zuletzt bearbeitet 19.08.2026 13:36:43
A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution t...
CVE-2026-21714
- EPSS 0.45%
- Veröffentlicht 30.03.2026 19:07:28
- Zuletzt bearbeitet 19.08.2026 13:35:56
A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Se...
CVE-2026-21715
- EPSS 0.16%
- Veröffentlicht 30.03.2026 19:07:28
- Zuletzt bearbeitet 19.08.2026 13:32:49
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permissio...