Multiple Vulnerabilities in Node.js (July 30, 2026)
Multiple vulnerabilities have been discovered in Node.js. Some of them allow an attacker to cause a remote denial of service, a breach of data confidentiality, and a breach of data integrity.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to cause a remote denial of service, breach data confidentiality, and breach data integrity.
- Who is affected
- All deployments of Node.js are affected by these vulnerabilities.
- Urgency
- Remediation is urgent due to the potential for remote denial of service and data breaches.
- Action
- Update to the latest version of Node.js to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Node.js
Get an email when a new Node.js advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0947/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-568500.08% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all scored CVEs.
- Low exploitation riskCVE-2026-580400.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2026-489340.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
- Low exploitation riskCVE-2026-568470.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Low exploitation riskCVE-2026-580390.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-56850 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56846 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58040 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48934 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58045 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58042 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56847 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56848 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58039 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58041 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58043 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58044 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Node.js: Multiple vulnerabilitiescert-bund
- lowCVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) f…nvd
- highCVE-2026-58043: A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-t…nvd
- mediumCVE-2026-58040: An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname…nvd
- mediumCVE-2026-56850: A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allo…nvd
- lowCVE-2026-56847: A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` …nvd
- unknownNode.js Multiple Vulnerabilitieshkcert
- high[UPDATE] [high] Node.js: Multiple vulnerabilitiescert-bund
- mediumCVE-2026-48934: A flaw in Node.js TLS host verification can cause an attacker to bypass certification validati…nvd
- unknownNode.js Multiple Vulnerabilitieshkcert
Recent advisories for Node.js
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-67320: axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-co…nvd · 2026-08-01
- unknownCVE-2026-67318: axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength li…nvd · 2026-08-01
- unknownCVE-2026-55100: hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.…nvd · 2026-07-31
- unknownCVE-2026-54729: DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense c…nvd · 2026-07-31
- medium[NEW] [medium] Node.js: Multiple vulnerabilitiescert-bund · 2026-07-31
- lowCVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) f…nvd · 2026-07-31
More from CERT-FR Avis de sécurité
- unknownMultiples vulnérabilités dans le noyau Linux d'Ubuntu (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de SUSE (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Red Hat (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans Progress MOVEit Transfer (31 juillet 2026)2026-07-31
- unknownMultiples vulnérabilités dans le noyau Linux de Debian LTS (31 juillet 2026)2026-07-31