[NEW] [medium] Node.js: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in Node.js to conduct a denial of service attack, bypass security measures, and manipulate files.
CSIRTS triage
- What
- Multiple vulnerabilities allow an attacker to conduct denial of service attacks and manipulate files.
- Who is affected
- Deployments of Node.js are affected.
- Urgency
- Remediation is medium priority as the vulnerabilities could disrupt services.
- Action
- Apply the latest updates for Node.js.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Node.js
Get an email when a new Node.js advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2585
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-489340.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
- Low exploitation riskCVE-2026-568470.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Low exploitation riskCVE-2026-568500.08% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all scored CVEs.
- Low exploitation riskCVE-2026-580390.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-580400.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2026-580430.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48934 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56846 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56847 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56848 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56850 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58039 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58040 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58041 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58042 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58043 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58044 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58045 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- lowCVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) f…nvd
- highCVE-2026-58043: A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-t…nvd
- mediumCVE-2026-58040: An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname…nvd
- mediumCVE-2026-56850: A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allo…nvd
- lowCVE-2026-56847: A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` …nvd
- unknownNode.js Multiple Vulnerabilitieshkcert
- unknownMultiple Vulnerabilities in Node.js (July 30, 2026)cert-fr-avis
- high[UPDATE] [high] Node.js: Multiple vulnerabilitiescert-bund
- mediumCVE-2026-48934: A flaw in Node.js TLS host verification can cause an attacker to bypass certification validati…nvd
- unknownNode.js Multiple Vulnerabilitieshkcert
Recent advisories for Node.js
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-67320: axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-co…nvd · 2026-08-01
- unknownCVE-2026-67318: axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength li…nvd · 2026-08-01
- unknownCVE-2026-55100: hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.…nvd · 2026-07-31
- unknownCVE-2026-54729: DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense c…nvd · 2026-07-31
- lowCVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) f…nvd · 2026-07-31
- mediumCVE-2026-68499: re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2…nvd · 2026-07-30
More from CERT-Bund (BSI) Security Advisories
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow Denial of Service2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities2026-07-31
- medium[UPDATE] [medium] Linux Kernel: Multiple vulnerabilities allow denial of service2026-07-31
- medium[UPDATE] [medium] Linux Kernel (ntfs3): Vulnerability allows information disclosure2026-07-31