CVE Tools

Node.js Security Updates: Urgent Action Required

Daily CyberSecurity (securityonline.info)By Do Son

PatchNode.js

Our summary

The Node.js project has issued critical and high-severity security updates that affect the 26.x, 24.x, and 22.x release lines, with patched versions listed as Node.js v22.23.1, v24.17.1, and v26.3.2. Among the fixed issues are CVE-2026-48933 (a WebCrypto AES integer overflow that can crash the process via subtle.encrypt()), and CVE-2026-48618 (a TLS authentication bypass tied to unicode dot separator handling). Additional vulnerabilities include CVE-2026-48615, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48617, CVE-2026-48935, CVE-2026-48936, and CVE-2026-48931, so organizations should upgrade promptly to reduce exposure to DoS and authentication/validation bypasses.

Read at Daily CyberSecurity (securityonline.info)

Daily CyberSecurity (securityonline.info) publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store