Security News

Cybersecurity news aggregator

🔓
HIGH Vulnerabilities HKCERT

Node.js Multiple Vulnerabilities

Multiple critical vulnerabilities in Node.js, including remote code execution, denial of service, and privilege escalation, can be exploited by a remote attacker. Affected versions are prior to 22.23.2 (LTS), prior to 24.18.1 (LTS), and prior to 26.5.1 (Current). The solution is to update to Node.js version 22.23.2, 24.18.1, or 26.5.1, respectively.
Read Full Article →

Multiple vulnerabilities have been identified in Node.js. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, security restriction bypass, sensitive information disclosure, remote code execution, data manipulation and spoofing on the targeted system... Impact Denial of Service Elevation of Privilege Spoofing Remote Code Execution Information Disclosure Data Manipulation Security Restriction Bypass System / Technologies affected Node.js versions prior to 22.23.2 (LTS) Node.js versions prior to 24.18.1 (LTS) Node.js versions prior to 26.5.1 (Current) Solutions Before installation of the software, please visit the vendor web-site for more details. Update to Node.js version 22.23.2 (LTS) Update to Node.js version 24.18.1 (LTS) Update to Node.js version 26.5.1 (Current)

Share this article