CVE-2026-48936
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
A flaw was found in Node.js. The Node.js Permission API can allow a local server to be started through a Unix domain socket, even when the `--allow-net` permission is not explicitly granted. This bypasses intended security restrictions, potentially leading to unintended local network exposure or integrity impact.
Metrics
Weakness classes (CWE)
CWE-284Pillar
Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
cwe.mitre.org →
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
bitnami
node-min22.22.3
bitnami
node-min24.16.0
bitnami
node-min26.3.0
IBM
App Connect Enterprise< 12.0.12.28
fixed in 12.0.12.28
IBM
App Connect Enterprise< 13.0.8.1
fixed in 13.0.8.1
IBM
App Connect Enterprise< 13.0.8.2
fixed in 13.0.8.2
IBM
Concert< 3.0.0
fixed in 3.0.0
juliangruber
brace-expansion5.0.0 – 5.0.6
References & sources
- https://nodejs.org/en/blog/vulnerability/june-2026-security-releasesweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-48619web
- https://github.com/nodeca/js-yaml/security/advisories/GHSA-g796-fgmg-93mvweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-59868advisory
- https://github.com/nodeca/js-yaml/commit/3105455b81dee69e0fd36e09ac0b2ccfdb54adc1web
- https://github.com/nodeca/js-yamlpackage
- https://github.com/nodeca/js-yaml/releases/tag/5.2.0web
- https://github.com/ljharb/qs/security/advisories/GHSA-q8mj-m7cp-5q26web
- https://nvd.nist.gov/vuln/detail/CVE-2026-8723advisory
- https://github.com/ljharb/qs/commit/21f80b33e5c8b3f7eba1034fff0da4a4a37a1d41web
- https://github.com/ljharb/qspackage
- https://github.com/nodeca/js-yaml/security/advisories/GHSA-724g-mxrg-4qvmweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-59870advisory
- https://github.com/nodeca/js-yaml/commit/39f3211a2f01b3c6982710cf21434ab7060acefeweb
- https://github.com/nodeca/js-yaml/releases/tag/5.2.1web
- https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-jxxr-4gwj-5jf2web
- https://nvd.nist.gov/vuln/detail/CVE-2026-45149advisory
- https://github.com/juliangruber/brace-expansion/commit/c0b095bdc52bc4c36dc88deddbadabc49f8371e5web
- https://github.com/juliangruber/brace-expansionpackage
- https://nvd.nist.gov/vuln/detail/CVE-2026-48936web
Linked CVEs
- CVE-2026-8723
A flaw was found in the `qs` library.
mediumCVSSv3 5.3 - CVE-2026-59870
A flaw was found in js-yaml, a JavaScript YAML (YAML Ain't Markup Language) parser.
highCVSSv3 7.5 - CVE-2026-59868
A flaw was found in js-yaml, a JavaScript YAML parser and dumper.
highCVSSv3 7.5 - CVE-2026-48935
A flaw was found in Node.js.
lowCVSSv3 3.3 - CVE-2026-48934
A flaw was found in Node.js.
mediumCVSSv3 4.3 - CVE-2026-48933
A flaw was found in the Node.js WebCrypto implementation.
highCVSSv3 7.5 - CVE-2026-48930
A flaw was found in Node.js.
mediumCVSSv3 5.6 - CVE-2026-48928
A flaw was found in Node.js.
mediumCVSSv3 4.2 - CVE-2026-48619
A flaw was found in Node.js.
mediumCVSSv3 5.3 - CVE-2026-48618
A flaw was found in Node.js.
highCVSSv3 7.7 - CVE-2026-48615
A flaw was found in Node.js.
mediumCVSSv3 5.9 - CVE-2026-45149
A flaw was found in the brace-expansion library.
highCVSSv3 7.5 - CVE-2026-2950
A flaw was found in Lodash.
mediumCVSSv3 6.5