CVE-2026-48933
CVSS Score
7.5
EPSS Score
2.8%
EPSS Percentile
85th
A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
| CWE | CWE-190 |
| Vendor | nodejs |
| Product | node |
| Ecosystems | |
| Industries | Technology |
| Published | Jun 26, 2026 |
| Last Updated | Jul 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for nodejs node
Be the first to know when new high vulnerabilities affecting nodejs node are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Affected Versions
nodejs / node
22.22.3 โค 22.22.3 24.16.0 โค 24.16.0 26.3.0 โค 26.3.0
References
nodejs.org: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases access.redhat.com: https://access.redhat.com/security/cve/CVE-2026-48933 bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2493331 security.access.redhat.com: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.json access.redhat.com: https://access.redhat.com/errata/RHSA-2026:39246 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:35842 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:35841 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:35892 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:35891 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:9455 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:28727 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:29012 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:7378 access.redhat.com: https://access.redhat.com/errata/RHSA-2026:30172