Node.js Multiple Vulnerabilities
CSIRTS triage
- What
- Multiple vulnerabilities have been reported in Node.js.
- Who is affected
- Users of Node.js are affected.
- Urgency
- Remediation is not urgent as there are no known exploits for these vulnerabilities.
- Action
- Check for updates and apply patches when available.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Node.js
Get an email when a new Node.js advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.hkcert.org/security-bulletin/node-js-multiple-vulnerabilities_20260730
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-489340.26% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 17% of all scored CVEs.
- Low exploitation riskCVE-2026-568470.15% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 5% of all scored CVEs.
- Low exploitation riskCVE-2026-568500.08% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 0% of all scored CVEs.
- Low exploitation riskCVE-2026-580390.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all scored CVEs.
- Low exploitation riskCVE-2026-580400.25% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all scored CVEs.
- Low exploitation riskCVE-2026-580430.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 3% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48934 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56846 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56847 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56848 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-56850 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58039 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58040 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58041 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58042 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58043 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58044 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58045 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[NEW] [medium] Node.js: Multiple vulnerabilitiescert-bund
- lowCVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) f…nvd
- highCVE-2026-58043: A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-t…nvd
- mediumCVE-2026-58040: An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname…nvd
- mediumCVE-2026-56850: A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allo…nvd
- lowCVE-2026-56847: A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` …nvd
- unknownMultiple Vulnerabilities in Node.js (July 30, 2026)cert-fr-avis
- high[UPDATE] [high] Node.js: Multiple vulnerabilitiescert-bund
- mediumCVE-2026-48934: A flaw in Node.js TLS host verification can cause an attacker to bypass certification validati…nvd
- unknownNode.js Multiple Vulnerabilitieshkcert
More from HKCERT Security Bulletins
- unknownGoogle Chrome Multiple Vulnerabilities2026-07-30
- unknownCisco Secure Firewall Management Center Software Information Disclosure Vulnerability2026-07-30
- unknownIBM WebSphere Products Multiple Vulnerabilities2026-07-30
- unknownXen Multiple Vulnerabilities2026-07-30
- unknownCitrix XenServer Multiple Vulnerabilities2026-07-30