CVE-2026-48933Patch(nodejs / node.js)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nodejs node.js systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-190CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node.js

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 7d ago at 1 mentions (2026-06-18); latest day: 1
  • 8 total mentions across 8 days

Affected systems

Vendors
Products
node.js

3 versions affected across 1 product

Deep dive

Activity timeline8 mentions / 8d
00111Mentions · 2026-06-18: 1Mentions · 2026-06-19: 1Mentions · 2026-06-21: 1Mentions · 2026-06-22: 1Mentions · 2026-06-25: 1Mentions · 2026-06-26: 1Mentions · 2026-07-02: 1Mentions · 2026-07-04: 1Patch / Workaround · 2026-06-18: 1Patch / Workaround · 2026-06-19: 1Patch / Workaround · 2026-06-21: 1Patch / Workaround · 2026-06-22: 1Patch / Workaround · 2026-06-25: 1Technical Details · 2026-06-19: 1Technical Details · 2026-06-21: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-26: 106-1806-1906-2106-2206-2506-2607-0207-04
Signal classification3 categories
Patch
562.5%
Disclosure
225.0%
General
112.5%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-181
Patch1
2026-06-191
Patch1
2026-06-211
Patch1
2026-06-221
Patch1
2026-06-251
Patch1
2026-06-261
Disclosure1
2026-07-021
Disclosure1
2026-07-041
General1
Full discourse8 posts
  • Daily CyberSecurity@the_yellow_fall
    Patch

    Protect your servers with the latest Node.js security updates. Patch critical vulnerabilities like CVE-2026-48933 to secure your infrastructure today. #NodeJS #SecurityUpdates #Cybersecurity #CVE #WebSecurity https://securityonline.info/nodejs-security-updates https://t.co/gAz8IUJpzm

    Post summary

    The tweet urges Node.js users to apply the latest security updates, specifically prompting a patch for CVE-2026-48933, with no exploit details or technical vulnerability information provided.

    01041445
    12.8K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos Node.js ❗ CVE-2026-48933 ❗ CVE-2026-48618 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-node-js-2/ https://t.co/HuO8PJ3WnA

    Post summary

    The tweet announces two new CVE identifiers affecting Node.js products and links to a CERT page for additional information.

    01020278
    6.7K followersView on X
  • Stuart 🇨🇷@stooee_
    General

    After analyzing 66% of vulnerabilities from past week, CVE-2026-48933 has 9 articles published from different internet sources, no other cve has these many articles. More information here: https://cves.st00ee.com/ #vulnerability #CyberSecurity #ThreatIntel #CVE #SecurityAlert

    Post summary

    The post notes that CVE-2026-48933 has drawn significant media attention, directing readers to an external link for more information, but it offers no technical details or evidence of exploitation.

    0000043
    75 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-48933 Denial of Service in Node.js WebCrypto Implementation via Large Input https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-48933

    Post summary

    CVE-2026-48933 is a Denial of Service vulnerability in Node.js WebCrypto caused by processing large inputs. The post merely announces the vulnerability; it does not provide PoC code, active exploitation evidence, or patch information.

    00000122
    4.1K followersView on X
  • Luis Torres@4Ndr3w10000
    Patch

    Node shipped security releases on June 18. CVE-2026-48933 is an integer overflow in WebCrypto subtle.encrypt() that can crash the process, and it affects every active line: 22.x, 24.x, 26.x. Patch to 22.23.0, 24.17.0, or 26.3.1. It is a real DoS, not theoretical. Update today.

    Post summary

    Node’s CVE-2026-48933 is an integer overflow in WebCrypto’s subtle.encrypt() that leads to a real denial‑of‑service; patches for releases 22.23.0, 24.17.0, and 26.3.1 are available and should be applied promptly.

    0000052
    35 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    Node.js、2026年6月のセキュリティリリースで12件の脆弱性を修正(CVE-2026-48933,CVE-2026-48618)他 https://rocket-boys.co.jp/security-measures-lab/nodejs-vulnerabilities-cve-2026-48933-cve-2026-48618/ #セキュリティ対策Lab #security #securitynews

    Post summary

    Node.js announced its June 2026 security release, fixing 12 vulnerabilities including CVE-2026-48933 and CVE-2026-48618, as noted by the linked security update.

    00000117
    436 followersView on X
  • Diego Artiles@dartilesm
    Patch

    🚨 Node.js patched all active LTS lines on June 18. CVE-2026-48618: IPv6 dots bypass TLS wildcard certs. CVE-2026-48933: WebCrypto AES crash, remote process abort. Patch to 22.23.0 / 24.17.0 / 26.3.1. How long before your team ships this?

    Post summary

    The text announces Node.js patches for CVE-2026-48618 and CVE-2026-48933, specifying affected LTS versions and providing the patched release numbers.

    0000045
    49 followersView on X
  • Can Artuc@canartuc
    Patch

    Node.js shipped 22.23.0, 24.17.0 and 26.3.1 on June 18, fixing 13 CVEs. Two are rated HIGH: CVE-2026-48933, a WebCrypto AES integer overflow that aborts the process, and CVE-2026-48618, a TLS wildcard-depth check fooled by a Unicode dot separator. Which release line do you run?

    Post summary

    Node.js released updates 22.23.0, 24.17.0, and 26.3.1 that patch two high‑severity CVEs affecting WebCrypto AES and TLS wildcard depth handling.

    0000047
    171 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js22.22.3--
Appnodejsnode.js24.16.0--
Appnodejsnode.js26.3.0--

Explore more