Multiple security vulnerabilities have been identified in Node.js, affecting its active branches: 22.x, 24.x, and 26.x. The overall risk/impact is high, as these flaws can crash servers and break filesystem restrictions.
CVE-2026-56846 (CVSS 9.8 — Critical): An attacker could send specially crafted traffic that consumes server memory, leading to a denial-of-service condition by enabling retained HTTP/2 header blocks to bypass the configured maxSessionMemory limit.[/subscribe_to_unlock_form]
Multiple security vulnerabilities have been identified in Node.js, affecting its active branches: 22.x, 24.x, and 26.x. The overall risk/impact is high, as these flaws can crash servers and break filesystem restrictions.
CVE-2026-56846 (CVSS 9.8 — Critical): An attacker could send specially crafted traffic that consumes server memory, leading to a denial-of-service condition by enabling retained HTTP/2 header blocks to bypass the configured maxSessionMemory limit.[emaillocker id="1283"]
CVE-2026-56848 (CVSS 9.1 — Critical): This vulnerability can trigger a heap use-after-free condition when the underlying nghttp2 library processes data while simultaneously receiving additional data, potentially crashing a process and having broader security implications depending on runtime conditions.
CVE-2026-58043 (CVSS 8.5 — High): Applications launched with the --permission option could mistakenly grant filesystem access outside the intended allowlist due to problems in radix-tree prefix boundary handling, allowing a user with access to an approved path to potentially read or write files in unintended locations.
CVE-2026-56850 (CVSS 7.5 — Medium): CVE-2026-56850 could result in HTTPS Agents reusing mutual TLS identities across requests with different PFX certificates.
CVE-2026-58040 (CVSS 7.5 — Medium): CVE-2026-58040 corrects an incomplete earlier patch that could permit TLS session reuse to bypass hostname verification across identity policies.
CVE-2026-58042 (CVSS 7.5 — Medium): CVE-2026-58042 can cause dns.resolveAny to abort when the response contains more than 256 A records, potentially causing a crash.
CVE-2026-58045 (CVSS 8.1 — High): CVE-2026-58045 can crash synchronous Node:zlib APIs when using a spoofed TypedArray byte length.
CVE-2026-58041 (CVSS 8.1 — High): CVE-2026-58041 can cause SQLite write re-execution due to a vulnerability in the Permission Model.
CVE-2026-56847 (CVSS 7.5 — Medium): CVE-2026-56847 allows writing files outside of paths authorized by --allow-fs-write due to a Permission Model bypass related to trace-event logs.
CVE-2026-58039 (CVSS 7.5 — Medium): CVE-2026-58039 also allows writing files outside of paths authorized by --allow-fs-write due to a Permission Model bypass related to process reports.
CVE-2026-58044 (CVSS 8.1 — High): CVE-2026-58044 fixes an issue with HTTP header truncation that could enable request smuggling in Node.js – based forwarding proxies. These vulnerabilities collectively present a significant risk, and administrators should upgrade immediately, test production dependencies, and retire unsupported Node.js versions. These vulnerabilities collectively present a significant risk, and administrators should upgrade immediately, test production dependencies, and retire unsupported Node.js versions.
These vulnerabilities collectively present a significant risk, and administrators should upgrade immediately, test production dependencies, and retire unsupported Node.js versions.
The following reports contain further technical details:
[/emaillocker]