Node.js Releases Security Updates for 12 Vulnerabilities, Two Rated High Severity
ID: 20c2f270-7182-5aca-b78d-93f96ec9be64
STIX ID: report--20c2f270-7182-5aca-b78d-93f96ec9be64
Feed Name: GBHackers
Node.js released critical security updates (June 18, 2026) addressing 12 vulnerabilities across Node.js 22.x, 24.x, and 26.x, including two high-severity issues that can cause remote DoS via WebCrypto integer overflow (CVE-2026-48933) and TLS authentication bypass via Unicode dot handling (CVE-2026-48618). The advisory lists multiple medium- and low-severity flaws impacting HTTP/2, TLS session reuse, proxy credential leakage, and permission-model bypasses; organizations are strongly urged to upgrade to patched versions v22.23.0, v24.17.0, or v26.3.1 immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
