Node.js — программная платформа, основанная на движке V8 (компилирующем JavaScript в машинный код)
Релизный цикл, информация об уязвимостях
График релизов
Релизные элементы
| KB | Версия | Билд | Дата доступности |
|---|---|---|---|
| 24.18.1 | 24.18.1 | ||
| 24.18.0 | 24.18.0 | ||
| 24.17.0 | 24.17.0 | ||
| 24.16.0 | 24.16.0 | ||
| 24.15.0 | 24.15.0 | ||
| 24.14.1 | 24.14.1 | ||
| 24.14.0 | 24.14.0 | ||
| 24.13.1 | 24.13.1 | ||
| 24.13.0 | 24.13.0 | ||
| 24.12.0 | 24.12.0 |
Показывать по
Количество 1 146
CVE-2026-48936
A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.
CVE-2026-48935
A flaw in Node.js Permission API can cause a file metadata to be modif ...
CVE-2026-48935
A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
CVE-2026-48934
A flaw in Node.js TLS host verification can cause an attacker to bypas ...
CVE-2026-48934
A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
CVE-2026-48933
A flaw in Node.js WebCrypto implementation can crash the process if th ...
CVE-2026-48933
A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
CVE-2026-48930
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnam ...
CVE-2026-48930
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
CVE-2026-48928
A inconsistency in Node.js hostname matching can cause a trust-policy ...
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2026-48936 A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**. | CVSS3: 3.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-48935 A flaw in Node.js Permission API can cause a file metadata to be modif ... | CVSS3: 3.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-48935 A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | CVSS3: 3.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-48934 A flaw in Node.js TLS host verification can cause an attacker to bypas ... | CVSS3: 4.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-48934 A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | CVSS3: 4.3 | 0% Низкий | около 1 месяца назад | |
CVE-2026-48933 A flaw in Node.js WebCrypto implementation can crash the process if th ... | CVSS3: 7.5 | 3% Низкий | около 1 месяца назад | |
CVE-2026-48933 A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | CVSS3: 7.5 | 3% Низкий | около 1 месяца назад | |
CVE-2026-48930 A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnam ... | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-48930 A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | CVSS3: 9.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-48928 A inconsistency in Node.js hostname matching can cause a trust-policy ... | CVSS3: 5.4 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу