Node.js developers released security updates
Node.js developers have released security updates to address multiple vulnerabilities (CVE-2026-48934, CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-56850, CVE-2026-58039, CVE-2026-58040, CVE-2026-58041, CVE-2026-58042, CVE-2026-58043, CVE-2026-58044, CVE-2026-58045). A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege, arbitrary code execution, data manipulation, security restriction bypass, sensitive information disclosure, spoofing and denial of service condition on the targeted system. The vulnerabilities were fixed in Node.js 26.5.1 (Current), Node.js 24.18.1 (LTS), Node.js 22.23.2 (LTS).
Source: nodejs.org
31 July 2026