CVE-2026-48933

Red Hat Security Advisory: nodejs:22 security update

Description

A flaw was found in the Node.js WebCrypto implementation. A remote attacker could exploit this vulnerability by providing an input to the `subtle.encrypt()` function that is a multiple of 2 gigabytes (GiB). This could lead to a denial of service (DoS) by crashing the Node.js process.

Metrics

Severity
high
no public PoC known
7.5
Source: nvd-v3
89.1 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
3.7 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-08-10 02:56 UTC
CWE-190

Weakness classes (CWE)

  • CWE-190Base

    Integer Overflow or Wraparound

    The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

    cwe.mitre.org →

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-08-10 13:19 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:52399
  2. CVE Modified2026-07-21 12:18 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:41947
    • Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+9)Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10.0 Extended Update Support (+9)
  3. CVE Modified2026-07-06 13:17 UTC· 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
    • Reference: https://access.redhat.com/errata/RHSA-2026:35841
    • Reference: https://access.redhat.com/errata/RHSA-2026:35842
    • Affected: Red Hat Hardened Images, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8 (+1)Red Hat Enterprise Linux AppStream (v. 10), Red Hat Hardened Images, Red Hat Enterprise Linux 8 (+1)

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • Atlassian

    BambooData Center LTS 10.2.22

  • Atlassian

    BambooData Center LTS 12.1.10

  • Atlassian

    BitbucketData Center 10.4.2

  • Atlassian

    BitbucketData Center LTS 10.2.6

  • Atlassian

    BitbucketData Center LTS 9.4.23

  • Atlassian

    ConfluenceData Center LTS 10.2.15

  • Atlassian

    ConfluenceData Center LTS 9.2.23

  • Atlassian

    Crucible4.9.13

  • Atlassian

    Fisheye4.9.13

  • Atlassian

    JiraData Center LTS 10.3.24

  • Atlassian

    JiraData Center LTS 11.3.10

  • beaugunderson

    ip-address10.1.1

  • bitnami

    node-min22.22.3

  • bitnami

    node-min24.16.0

  • bitnami

    node-min26.3.0

  • nodejs

    undici6.17.0 – 6.27.0

  • nodejs

    undici7.0.0 – 7.28.0

  • nodejs

    undici8.0.0 – 8.5.0

References & sources

Linked CVEs

IDCVE-2026-48933