Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities HKCERT

Node.js Multiple Vulnerabilities

Multiple vulnerabilities in Node.js, including those enabling denial of service, security restriction bypass, data manipulation, information disclosure, and spoofing, could be exploited by a remote attacker. Affected versions include Node.js prior to 22.23.0 (LTS), prior to 24.17.0 (LTS), and prior to 26.3.1 (Current). The solution is to update to Node.js version 22.23.0, 24.17.0, or 26.3.1, respectively.
Read Full Article →

Multiple vulnerabilities have been identified in Node.js. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, data manipulation, security restriction bypass, spoofing and sensitive information disclosure on the targeted system. Impact Denial of Service Security Restriction Bypass Data Manipulation Information Disclosure Spoofing System / Technologies affected Node.js versions prior to 22.23.0 (LTS) Node.js versions prior to 24.17.0 (LTS) Node.js versions prior to 26.3.1 (Current) Solutions Before installation of the software, please visit the vendor web-site for more details. Update to Node.js version 22.23.0 (LTS) Update to Node.js version 24.17.0 (LTS) Update to Node.js version 26.3.1 (Current)

Share this article