[WID-SEC-2026-2004] Node.js: Mehrere Schwachstellen CVSS Base Score 9.8 (kritisch) CVSS Temporal Score 8.5 (hoch) Remoteangriff ja Datum 18.06.2026 Stand 19.06.2026 Mitigation ja Betroffene Systeme Betriebssystem Sonstiges UNIX Windows Produktbeschreibung Node.js ist eine Plattform zur Entwicklung von Netzwerkanwendungen. Produkte 18.06.2026 Open Source Node.js <22.23.0 Open Source Node.js <24.17.0 Open Source Node.js <26.3.1 Angriff Angriff Ein Angreifer kann mehrere Schwachstellen in Node.js ausnutzen, um Sicherheitsvorkehrungen zu umgehen, Daten zu manipulieren, vertrauliche Informationen offenzulegen oder einen Denial-of-Service-Zustand zu verursachen. CVE Informationen Versionshistorie Feedback zum Advisory geben
A critical vulnerability (CVSS Base Score 9.8) in Node.js allows a remote attacker to bypass security controls, manipulate data, disclose sensitive information, or cause a denial of service. Affected versions include Node.js versions prior to 22.23.0, prior to 24.17.0, and prior to 26.3.1, requiring an immediate upgrade to these respective fixed versions.