Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48933

Опубликовано: 26 июн. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw in Node.js WebCrypto implementation can crash the process if the input of subtle.encrypt() is a multiple of 2GiB. This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.

A flaw was found in the Node.js WebCrypto implementation. A remote attacker could exploit this vulnerability by providing an input to the subtle.encrypt() function that is a multiple of 2 gigabytes (GiB). This could lead to a denial of service (DoS) by crashing the Node.js process.

Отчет

This is an Important denial of service vulnerability in Node.js WebCrypto, as a remote attacker can crash the Node.js process by providing a specially crafted large input to the subtle.encrypt() function. This could lead to service unavailability in Red Hat environments where Node.js applications process untrusted data with WebCrypto.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nodejs22Affected
Red Hat Enterprise Linux 10nodejs24Affected
Red Hat Enterprise Linux 8nodejs:22/nodejsAffected
Red Hat Enterprise Linux 8nodejs:24/nodejsAffected
Red Hat Enterprise Linux 9nodejs:22/nodejsAffected
Red Hat Enterprise Linux 9nodejs:24/nodejsAffected
Red Hat Hardened Imagesnodejs22-main-22.23.1-1.hum1FixedRHSA-2026:2872724.06.2026
Red Hat Hardened Imagesnodejs24-main-24.18.0-0.1.hum1FixedRHSA-2026:2901224.06.2026
Red Hat Hardened Imagesnodejs26-main-26.4.0-1.2.hum1FixedRHSA-2026:3017225.06.2026
Red Hat Hardened Imagesnodejs25-main-25.9.0-1.1.hum1FixedRHSA-2026:737810.04.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2493331nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt()

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
nvd
около 1 месяца назад

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
debian
около 1 месяца назад

A flaw in Node.js WebCrypto implementation can crash the process if th ...

CVSS3: 7.5
github
около 1 месяца назад

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

suse-cvrf
около 1 месяца назад

Security update for nodejs22

7.5 High

CVSS3