VORANT. Threat Intelligence Sign in Get the full feed

Node.js patches multiple 2026 vulnerabilities

medium vulnerability technology

CERT-FR advisory details 12 vulnerabilities in Node.js 22.x, 24.x, and 26.x that could enable denial of service, data confidentiality, and integrity breaches.

CERT-FR issued an advisory covering multiple vulnerabilities discovered in Node.js affecting versions 22.x prior to 22.23.2, 24.x prior to 24.18.1, and 26.x prior to 26.5.1. The vulnerabilities, tracked under twelve separate CVE identifiers, can allow an attacker to cause remote denial of service, compromise data confidentiality, and undermine data integrity, depending on the specific flaw exploited.

No evidence of active exploitation is mentioned in the advisory. Node.js has published an official security bulletin (july-2026-security-releases) with patches addressing all identified issues. Organizations running affected Node.js versions should apply the vendor-provided updates as described in the referenced documentation to mitigate these risks.

Mentioned in this report

Vulnerabilities CVE-2026-48934CVE-2026-56846CVE-2026-56847CVE-2026-56848CVE-2026-56850CVE-2026-58039CVE-2026-58040CVE-2026-58041CVE-2026-58042CVE-2026-58043CVE-2026-58044CVE-2026-58045

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0947

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free