news.mlab.sh
Back to the feed
vulnerability

Multiples vulnérabilités dans Node.js (30 juillet 2026)

Medium
Summary

Multiple vulnerabilities have been discovered in Node.js, impacting versions 22.x, 24.x, and 26.x prior to the specified release dates. These vulnerabilities can lead to data integrity compromise, data confidentiality issues, and denial-of-service attacks. Users are advised to consult the Node.js security bulletin for available patches.

A security bulletin from CERT-FR details multiple vulnerabilities affecting Node.js. These vulnerabilities are present in versions 22.x (prior to 22.23.2), 24.x (prior to 24.18.1), and 26.x (prior to 26.5.1). The bulletin highlights potential risks including data integrity compromise, data confidentiality issues, and the ability to trigger a denial-of-service attack. CERT-FR has published a security bulletin with detailed information and recommended solutions. The CVE identifiers associated with these vulnerabilities are CVE-2026-48934, CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-58039, CVE-2026-58040, CVE-2026-58041, CVE-2026-58042, CVE-2026-58043, and CVE-2026-58044. Users should refer to the Node.js security bulletin for the latest information and to apply the necessary security updates.

Read the full article at CERT-FR