Количество 20
Количество 20
BDU:2026-04838
Уязвимость функции fs.realpathSync.native() программной платформы Node.js, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
CVE-2026-21715
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted.
CVE-2026-21715
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted.
CVE-2026-21715
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted.
CVE-2026-21715
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted.
CVE-2026-21715
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.r ...
GHSA-8jgr-5cgv-g667
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted.
SUSE-SU-2026:1509-1
Security update for nodejs22
SUSE-SU-2026:1478-1
Security update for nodejs22
SUSE-SU-2026:1371-1
Security update for nodejs20
SUSE-SU-2026:1363-1
Security update for nodejs20
openSUSE-SU-2026:20519-1
Security update for nodejs24
SUSE-SU-2026:1299-1
Security update for nodejs24
RLSA-2026:7670
Important: nodejs:24 security update
ELSA-2026-7670
ELSA-2026-7670: nodejs:24 security update (IMPORTANT)
RLSA-2026:7675
Important: nodejs24 security update
RLSA-2026:7350
Important: nodejs:24 security update
ELSA-2026-7675
ELSA-2026-7675: nodejs24 security update (IMPORTANT)
ELSA-2026-7350
ELSA-2026-7350: nodejs:24 security update (IMPORTANT)
openSUSE-SU-2026:21058-1
Security update for nodejs22
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-04838 Уязвимость функции fs.realpathSync.native() программной платформы Node.js, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации | CVSS3: 3.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-21715 A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted. | CVSS3: 3.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-21715 A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted. | CVSS3: 3.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-21715 A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted. | CVSS3: 3.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-21715 A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted. | CVSS3: 3.3 | 0% Низкий | 4 месяца назад | |
CVE-2026-21715 A flaw in Node.js Permission Model filesystem enforcement leaves `fs.r ... | CVSS3: 3.3 | 0% Низкий | 4 месяца назад | |
GHSA-8jgr-5cgv-g667 A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs-read` can still use `fs.realpathSync.native()` to check file existence, resolve symlink targets, and enumerate filesystem paths outside of permitted directories. This vulnerability affects **20.x, 22.x, 24.x, and 25.x** processes using the Permission Model where `--allow-fs-read` is intentionally restricted. | CVSS3: 3.3 | 0% Низкий | 4 месяца назад | |
SUSE-SU-2026:1509-1 Security update for nodejs22 | 3 месяца назад | |||
SUSE-SU-2026:1478-1 Security update for nodejs22 | 3 месяца назад | |||
SUSE-SU-2026:1371-1 Security update for nodejs20 | 4 месяца назад | |||
SUSE-SU-2026:1363-1 Security update for nodejs20 | 4 месяца назад | |||
openSUSE-SU-2026:20519-1 Security update for nodejs24 | 4 месяца назад | |||
SUSE-SU-2026:1299-1 Security update for nodejs24 | 4 месяца назад | |||
RLSA-2026:7670 Important: nodejs:24 security update | 4 месяца назад | |||
ELSA-2026-7670 ELSA-2026-7670: nodejs:24 security update (IMPORTANT) | 4 месяца назад | |||
RLSA-2026:7675 Important: nodejs24 security update | 4 месяца назад | |||
RLSA-2026:7350 Important: nodejs:24 security update | 4 месяца назад | |||
ELSA-2026-7675 ELSA-2026-7675: nodejs24 security update (IMPORTANT) | около 2 месяцев назад | |||
ELSA-2026-7350 ELSA-2026-7350: nodejs:24 security update (IMPORTANT) | 4 месяца назад | |||
openSUSE-SU-2026:21058-1 Security update for nodejs22 | около 1 месяца назад |
Уязвимостей на страницу