# Node.js patches multiple 2026 vulnerabilities

Published: 2026-07-30 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/e82d81b3-82ee-52cc-8b83-511110baae61/node-js-patches-multiple-2026-vulnerabilities

> CERT-FR advisory details 12 vulnerabilities in Node.js 22.x, 24.x, and 26.x that could enable denial of service, data confidentiality, and integrity breaches.

CERT-FR issued an advisory covering multiple vulnerabilities discovered in Node.js affecting versions 22.x prior to 22.23.2, 24.x prior to 24.18.1, and 26.x prior to 26.5.1. The vulnerabilities, tracked under twelve separate CVE identifiers, can allow an attacker to cause remote denial of service, compromise data confidentiality, and undermine data integrity, depending on the specific flaw exploited.

No evidence of active exploitation is mentioned in the advisory. Node.js has published an official security bulletin (july-2026-security-releases) with patches addressing all identified issues. Organizations running affected Node.js versions should apply the vendor-provided updates as described in the referenced documentation to mitigate these risks.

## Mentioned in this report

- Vulnerabilities: CVE-2026-48934, CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-56850, CVE-2026-58039, CVE-2026-58040, CVE-2026-58041, CVE-2026-58042, CVE-2026-58043, CVE-2026-58044, CVE-2026-58045

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0947

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/e82d81b3-82ee-52cc-8b83-511110baae61/node-js-patches-multiple-2026-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
