Количество 19
Количество 19
BDU:2026-04835
Уязвимость функции memcmp программной платформы Node.js, связанная с недостаточным сравнением, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
CVE-2026-21713
A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-21713
A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-21713
A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-21713
A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
CVE-2026-21713
A flaw in Node.js HMAC verification uses a non-constant-time compariso ...
GHSA-6r7g-3mm3-fhw7
A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**.
SUSE-SU-2026:1509-1
Security update for nodejs22
SUSE-SU-2026:1478-1
Security update for nodejs22
SUSE-SU-2026:1371-1
Security update for nodejs20
SUSE-SU-2026:1363-1
Security update for nodejs20
openSUSE-SU-2026:20519-1
Security update for nodejs24
SUSE-SU-2026:1299-1
Security update for nodejs24
RLSA-2026:7670
Important: nodejs:24 security update
ELSA-2026-7670
ELSA-2026-7670: nodejs:24 security update (IMPORTANT)
RLSA-2026:7675
Important: nodejs24 security update
RLSA-2026:7350
Important: nodejs:24 security update
ELSA-2026-7675
ELSA-2026-7675: nodejs24 security update (IMPORTANT)
ELSA-2026-7350
ELSA-2026-7350: nodejs:24 security update (IMPORTANT)
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-04835 Уязвимость функции memcmp программной платформы Node.js, связанная с недостаточным сравнением, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 5.9 | 0% Низкий | 4 месяца назад | |
CVE-2026-21713 A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**. | CVSS3: 5.9 | 0% Низкий | 4 месяца назад | |
CVE-2026-21713 A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**. | CVSS3: 5.9 | 0% Низкий | 4 месяца назад | |
CVE-2026-21713 A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**. | CVSS3: 5.9 | 0% Низкий | 4 месяца назад | |
CVE-2026-21713 A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**. | CVSS3: 5.9 | 0% Низкий | 4 месяца назад | |
CVE-2026-21713 A flaw in Node.js HMAC verification uses a non-constant-time compariso ... | CVSS3: 5.9 | 0% Низкий | 4 месяца назад | |
GHSA-6r7g-3mm3-fhw7 A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possible, this behavior could be exploited as a timing oracle to infer HMAC values. Node.js already provides timing-safe comparison primitives used elsewhere in the codebase, indicating this is an oversight rather than an intentional design decision. This vulnerability affects **20.x, 22.x, 24.x, and 25.x**. | CVSS3: 5.9 | 0% Низкий | 4 месяца назад | |
SUSE-SU-2026:1509-1 Security update for nodejs22 | 3 месяца назад | |||
SUSE-SU-2026:1478-1 Security update for nodejs22 | 3 месяца назад | |||
SUSE-SU-2026:1371-1 Security update for nodejs20 | 4 месяца назад | |||
SUSE-SU-2026:1363-1 Security update for nodejs20 | 4 месяца назад | |||
openSUSE-SU-2026:20519-1 Security update for nodejs24 | 4 месяца назад | |||
SUSE-SU-2026:1299-1 Security update for nodejs24 | 4 месяца назад | |||
RLSA-2026:7670 Important: nodejs:24 security update | 4 месяца назад | |||
ELSA-2026-7670 ELSA-2026-7670: nodejs:24 security update (IMPORTANT) | 4 месяца назад | |||
RLSA-2026:7675 Important: nodejs24 security update | 4 месяца назад | |||
RLSA-2026:7350 Important: nodejs:24 security update | 4 месяца назад | |||
ELSA-2026-7675 ELSA-2026-7675: nodejs24 security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-7350 ELSA-2026-7350: nodejs:24 security update (IMPORTANT) | 4 месяца назад |
Уязвимостей на страницу