Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48931

Опубликовано: 22 июн. 2026
Источник: redhat
CVSS3: 3.7
EPSS Низкий

Описание

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.

A flaw was found in Node.js HTTP Agent. This vulnerability allows a client to accept a server response as valid even before the client has sent its request. This can lead to unexpected behavior and potentially information disclosure.

Отчет

This is a Low impact flaw in the Node.js HTTP Agent where a client may prematurely accept and process an HTTP response before its corresponding request has been fully sent. This could lead to a client misinterpreting data or entering an unexpected state. Exploitation requires high attack complexity, limiting the practical risk in most Red Hat deployments.

Меры по смягчению последствий

Limit outbound HTTP/1.1 from Node.js clients to trusted backend endpoints with egress firewall rules or network segmentation. Avoid keep-alive connection pools to untrusted hosts where operationally feasible.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nodejs22Not affected
Red Hat Enterprise Linux 10nodejs24Not affected
Red Hat Enterprise Linux 8nodejs:22/nodejsNot affected
Red Hat Enterprise Linux 8nodejs:24/nodejsNot affected
Red Hat Enterprise Linux 9nodejs:22/nodejsNot affected
Red Hat Enterprise Linux 9nodejs:24/nodejsNot affected
Red Hat Enterprise Linux 9nodejs:26/nodejsFix deferred
Red Hat Hardened Imagesnodejs20Not affected
Red Hat Hardened Imagesnodejs22Not affected
Red Hat Hardened Imagesnodejs24Not affected

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-367
https://bugzilla.redhat.com/show_bug.cgi?id=2491494nodejs: Node.js HTTP Agent: Information disclosure due to premature response acceptance

EPSS

Процентиль: 27%
0.00345
Низкий

3.7 Low

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
3 месяца назад

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 3.7
nvd
3 месяца назад

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 3.7
debian
3 месяца назад

A flaw in Node.js HTTP Agent can cause a client to accept as valid a r ...

CVSS3: 3.7
redos
28 дней назад

Уязвимость nodejs24

CVSS3: 3.7
redos
28 дней назад

Уязвимость nodejs

EPSS

Процентиль: 27%
0.00345
Низкий

3.7 Low

CVSS3

Уязвимость CVE-2026-48931