nodejs node
4 known vulnerabilities in nodejs node, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-48932 CVSS 3.7 low A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers…
- CVE-2026-56848 CVSS 7.5 high A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is…
- CVE-2026-56846 CVSS 7.5 high A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This…
- CVE-2026-58043 CVSS 8.4 high A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`…