Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 1 146

Количество 1 146

redhat логотип

CVE-2026-48936

около 1 месяца назад

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2026-48936

около 1 месяца назад

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.

CVSS3: 3.3
EPSS: Низкий
debian логотип

CVE-2026-48936

около 1 месяца назад

A flaw in Node.js Permission API can cause a local server to be starte ...

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2026-48935

около 1 месяца назад

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 3.3
EPSS: Низкий
redhat логотип

CVE-2026-48935

около 1 месяца назад

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 3.3
EPSS: Низкий
nvd логотип

CVE-2026-48935

около 1 месяца назад

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 3.3
EPSS: Низкий
debian логотип

CVE-2026-48935

около 1 месяца назад

A flaw in Node.js Permission API can cause a file metadata to be modif ...

CVSS3: 3.3
EPSS: Низкий
ubuntu логотип

CVE-2026-48934

около 1 месяца назад

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 4.3
EPSS: Низкий
redhat логотип

CVE-2026-48934

около 1 месяца назад

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-48934

около 1 месяца назад

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2026-48934

около 1 месяца назад

A flaw in Node.js TLS host verification can cause an attacker to bypas ...

CVSS3: 4.3
EPSS: Низкий
ubuntu логотип

CVE-2026-48933

около 1 месяца назад

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2026-48933

около 1 месяца назад

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-48933

около 1 месяца назад

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-48933

около 1 месяца назад

A flaw in Node.js WebCrypto implementation can crash the process if th ...

CVSS3: 7.5
EPSS: Низкий
ubuntu логотип

CVE-2026-48931

около 1 месяца назад

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2026-48931

около 1 месяца назад

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2026-48931

около 1 месяца назад

A flaw in Node.js HTTP Agent can cause a client to accept as valid a r ...

CVSS3: 3.7
EPSS: Низкий
ubuntu логотип

CVE-2026-48930

около 1 месяца назад

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 9.8
EPSS: Низкий
redhat логотип

CVE-2026-48930

около 1 месяца назад

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 5.6
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-48936

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.

CVSS3: 3.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-48936

A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission. This vulnerability affects one supported release line: **Node.js 26**.

CVSS3: 3.3
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-48936

A flaw in Node.js Permission API can cause a local server to be starte ...

CVSS3: 3.3
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-48935

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 3.3
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-48935

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 3.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-48935

A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 3.3
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-48935

A flaw in Node.js Permission API can cause a file metadata to be modif ...

CVSS3: 3.3
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-48934

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-48934

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-48934

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-48934

A flaw in Node.js TLS host verification can cause an attacker to bypas ...

CVSS3: 4.3
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-48933

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
4%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-48933

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
4%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-48933

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 7.5
4%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-48933

A flaw in Node.js WebCrypto implementation can crash the process if th ...

CVSS3: 7.5
4%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-48931

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 3.7
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-48931

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 3.7
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-48931

A flaw in Node.js HTTP Agent can cause a client to accept as valid a r ...

CVSS3: 3.7
0%
Низкий
около 1 месяца назад
ubuntu логотип
CVE-2026-48930

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 9.8
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-48930

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 5.6
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу