# Node.js patches 13 vulnerabilities in June releases

Published: 2026-06-19 · Severity: medium
Canonical: https://vorant.io/reports/ff8b6b8f-7cba-5c32-9d39-a608a0bf6625/node-js-patches-13-vulnerabilities-in-june-releases

> Multiple vulnerabilities in Node.js versions 22.x, 24.x, and 26.x allow remote denial of service, data confidentiality and integrity attacks.

The French CERT has issued an advisory for multiple vulnerabilities discovered in Node.js runtime versions 22.x (prior to 22.23.0), 24.x (prior to 24.17.0), and 26.x (prior to 26.3.1). The vulnerabilities enable attackers to perform remote denial of service attacks, compromise data confidentiality and integrity, and bypass security policies.

Thirteen CVEs were assigned to these flaws (CVE-2026-21636, CVE-2026-48615, CVE-2026-48617, CVE-2026-48618, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48931, CVE-2026-48933, CVE-2026-48934, CVE-2026-48935, CVE-2026-48936, CVE-2026-48937). The Node.js project released security updates on June 18, 2026 to address these issues. Organizations running affected versions should refer to the official Node.js security bulletin and apply the patches to the latest versions in each release line.

## Mentioned in this report

- Vulnerabilities: CVE-2026-21636, CVE-2026-48615, CVE-2026-48617, CVE-2026-48618, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48931, CVE-2026-48933, CVE-2026-48934, CVE-2026-48935, CVE-2026-48936, CVE-2026-48937

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0786/

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/ff8b6b8f-7cba-5c32-9d39-a608a0bf6625/node-js-patches-13-vulnerabilities-in-june-releases.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
