Threat Advisory

Node.js Fixes 11 Security Flaws That Can Crash Servers and Break Filesystem Restrictions

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Node.js, affecting its active branches: 22.x, 24.x, and 26.x. The overall risk/impact is high, as these flaws can crash servers and break filesystem restrictions.

CVE-2026-56846 (CVSS 9.8 — Critical): An attacker could send specially crafted traffic that consumes server memory, leading to a denial-of-service condition by enabling retained HTTP/2 header blocks to bypass the configured maxSessionMemory limit.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

Multiple security vulnerabilities have been identified in Node.js, affecting its active branches: 22.x, 24.x, and 26.x. The overall risk/impact is high, as these flaws can crash servers and break filesystem restrictions.

CVE-2026-56846 (CVSS 9.8 — Critical): An attacker could send specially crafted traffic that consumes server memory, leading to a denial-of-service condition by enabling retained HTTP/2 header blocks to bypass the configured maxSessionMemory limit.[emaillocker id="1283"]

CVE-2026-56848 (CVSS 9.1 — Critical): This vulnerability can trigger a heap use-after-free condition when the underlying nghttp2 library processes data while simultaneously receiving additional data, potentially crashing a process and having broader security implications depending on runtime conditions.

CVE-2026-58043 (CVSS 8.5 — High): Applications launched with the --permission option could mistakenly grant filesystem access outside the intended allowlist due to problems in radix-tree prefix boundary handling, allowing a user with access to an approved path to potentially read or write files in unintended locations.

CVE-2026-56850 (CVSS 7.5 — Medium): CVE-2026-56850 could result in HTTPS Agents reusing mutual TLS identities across requests with different PFX certificates.

CVE-2026-58040 (CVSS 7.5 — Medium): CVE-2026-58040 corrects an incomplete earlier patch that could permit TLS session reuse to bypass hostname verification across identity policies.

CVE-2026-58042 (CVSS 7.5 — Medium): CVE-2026-58042 can cause dns.resolveAny to abort when the response contains more than 256 A records, potentially causing a crash.

CVE-2026-58045 (CVSS 8.1 — High): CVE-2026-58045 can crash synchronous Node:zlib APIs when using a spoofed TypedArray byte length.

CVE-2026-58041 (CVSS 8.1 — High): CVE-2026-58041 can cause SQLite write re-execution due to a vulnerability in the Permission Model.

CVE-2026-56847 (CVSS 7.5 — Medium): CVE-2026-56847 allows writing files outside of paths authorized by --allow-fs-write due to a Permission Model bypass related to trace-event logs.

CVE-2026-58039 (CVSS 7.5 — Medium): CVE-2026-58039 also allows writing files outside of paths authorized by --allow-fs-write due to a Permission Model bypass related to process reports.

CVE-2026-58044 (CVSS 8.1 — High): CVE-2026-58044 fixes an issue with HTTP header truncation that could enable request smuggling in Node.js – based forwarding proxies. These vulnerabilities collectively present a significant risk, and administrators should upgrade immediately, test production dependencies, and retire unsupported Node.js versions. These vulnerabilities collectively present a significant risk, and administrators should upgrade immediately, test production dependencies, and retire unsupported Node.js versions.

These vulnerabilities collectively present a significant risk, and administrators should upgrade immediately, test production dependencies, and retire unsupported Node.js versions.

RECOMMENDATIONS:

  • We recommend you to update Node.js to version 22.23.2.
  • We recommend you to update Undici dependency to version 8.9.0, 7.29.0, or 6.28.0.

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu