Node.js Multiple Vulnerabilities
Release Date:
22 Jun 2026
286
Views
RISK: Medium Risk
TYPE: Servers - Other Servers

Multiple vulnerabilities have been identified in Node.js. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, data manipulation, security restriction bypass, spoofing and sensitive information disclosure on the targeted system.
Impact
- Denial of Service
- Security Restriction Bypass
- Data Manipulation
- Information Disclosure
- Spoofing
System / Technologies affected
- Node.js versions prior to 22.23.0 (LTS)
- Node.js versions prior to 24.17.0 (LTS)
- Node.js versions prior to 26.3.1 (Current)
Solutions
Before installation of the software, please visit the vendor web-site for more details.
- Update to Node.js version 22.23.0 (LTS)
- Update to Node.js version 24.17.0 (LTS)
- Update to Node.js version 26.3.1 (Current)
Vulnerability Identifier
- CVE-2026-48615
- CVE-2026-48617
- CVE-2026-48618
- CVE-2026-48619
- CVE-2026-48928
- CVE-2026-48930
- CVE-2026-48931
- CVE-2026-48933
- CVE-2026-48934
- CVE-2026-48935
- CVE-2026-48936
- CVE-2026-48937
Source
Related Link
Related Tags
Share with
