CVE-2026-48936

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Description

A flaw was found in Node.js. The Node.js Permission API can allow a local server to be started through a Unix domain socket, even when the `--allow-net` permission is not explicitly granted. This bypasses intended security restrictions, potentially leading to unintended local network exposure or integrity impact.

Metrics

Severity
low
no public PoC known
3.3
Source: nvd-v3
3.3 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
0.1 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-04-21 17:31 UTC
CWE-284

Weakness classes (CWE)

  • CWE-284Pillar

    Improper Access Control

    The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

    cwe.mitre.org →

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    node-min22.22.3

  • bitnami

    node-min24.16.0

  • bitnami

    node-min26.3.0

  • IBM

    App Connect Enterprise< 12.0.12.28

    fixed in 12.0.12.28

  • IBM

    App Connect Enterprise< 13.0.8.1

    fixed in 13.0.8.1

  • IBM

    App Connect Enterprise< 13.0.8.2

    fixed in 13.0.8.2

  • IBM

    Concert< 3.0.0

    fixed in 3.0.0

  • juliangruber

    brace-expansion5.0.0 – 5.0.6

References & sources

Linked CVEs

IDCVE-2026-48936