CVE-2026-48933
Red Hat Security Advisory: nodejs:22 security update
Description
A flaw was found in the Node.js WebCrypto implementation. A remote attacker could exploit this vulnerability by providing an input to the `subtle.encrypt()` function that is a multiple of 2 gigabytes (GiB). This could lead to a denial of service (DoS) by crashing the Node.js process.
Metrics
Weakness classes (CWE)
CWE-190Base
Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
cwe.mitre.org →
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-08-10 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:52399
- CVE Modified2026-07-21 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:41947
- Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+9) → Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+9)
- CVE Modified2026-07-06 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
- Reference: https://access.redhat.com/errata/RHSA-2026:35841
- Reference: https://access.redhat.com/errata/RHSA-2026:35842
- Affected: Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 (+1) → Red Hat Enterprise Linux AppStream (v. 10), Red Hat Hardened Images, Red Hat Enterprise Linux 8 (+1)
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
Atlassian
BambooData Center LTS 10.2.22
Atlassian
BambooData Center LTS 12.1.10
Atlassian
BitbucketData Center 10.4.2
Atlassian
BitbucketData Center LTS 10.2.6
Atlassian
BitbucketData Center LTS 9.4.23
Atlassian
ConfluenceData Center LTS 10.2.15
Atlassian
ConfluenceData Center LTS 9.2.23
Atlassian
Crucible4.9.13
Atlassian
Fisheye4.9.13
Atlassian
JiraData Center LTS 10.3.24
Atlassian
JiraData Center LTS 11.3.10
beaugunderson
ip-address10.1.1
bitnami
node-min22.22.3
bitnami
node-min24.16.0
bitnami
node-min26.3.0
nodejs
undici6.17.0 – 6.27.0
nodejs
undici7.0.0 – 7.28.0
nodejs
undici8.0.0 – 8.5.0
References & sources
- https://github.com/isaacs/node-tar/security/advisories/GHSA-8x88-c5mf-7j5wweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-59874advisory
- https://github.com/isaacs/node-tar/commit/9e78bf058b2c22dd4d52e00d8922d5c06fc2f7b5web
- https://github.com/isaacs/node-tarpackage
- https://github.com/isaacs/node-tar/releases/tag/v7.5.18web
- https://nodejs.org/en/blog/vulnerability/june-2026-security-releasesweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-48615web
- https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89qweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-12151advisory
- https://cna.openjsf.org/security-advisories.htmlweb
- https://github.com/nodejs/undicipackage
- https://access.redhat.com/security/cve/CVE-2026-12151vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2489980issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:48151vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:39246vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:35842vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:35841vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:41947vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:39868vendor-advisoryx_refsource_REDHAT
Linked CVEs
- CVE-2026-59874
A flaw was found in node-tar, a tar archive manipulation library for Node.js.
highCVSSv3 7.5 - CVE-2026-59873
A flaw was found in node-tar, a tar archive manipulation library for Node.js.
criticalCVSSv3 7.5 - CVE-2026-48618
A flaw was found in Node.js.
highCVSSv3 7.7 - CVE-2026-48615
A flaw was found in Node.js.
mediumCVSSv3 5.9 - CVE-2026-42338
A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses.
highCVSSv3 8.1 - CVE-2026-13149
A flaw was found in brace-expansion.
high - CVE-2026-12151
A flaw was found in undici.
highCVSSv3 7.5