Threat reportVulnerabilityTL-2026-1807
Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass, TLS/mTLS Issues)
Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1 (TL-2026-1807), also tracked as Node.js July 2026 Security Releases, is a high-severity software vulnerability scored CVSS 7.5, first published 2026-08-01. It has no confirmed attribution, affects OpenJS Foundation / Node.js Project Node.js (v22.x 'Jod' LTS), references 12 CVEs (CVE-2026-56846, CVE-2026-56847, CVE-2026-56848), maps to 18 MITRE ATT&CK techniques (T1005, T1059, T1068), and is covered by 9 detection rules and 34 indicators of compromise.
- CVSS
- 7.5/10High
- CVEs
- 12Referenced vulnerabilities
- Techniques
- 18MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 34Indicators of compromise
Key facts for TL-2026-1807
- Threat ID
- TL-2026-1807
- Also known as
- Node.js July 2026 Security Releases
- Severity
- HIGH
- CVSS
- 7.5 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N)
- Status
- PATCHED
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, cloud-hosting-saas, ecommerce, financial-services, government administration, health, telecoms, media-and-entertainment
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 34
Malware and tooling in Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1
Malware and tooling: nghttp2
How Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1 works
Node.js released v22.23.2, v24.18.1, and v26.5.1 on 2026-07-29 fixing 11 CVEs, including three HIGH-severity issues: an HTTP/2 flaw letting retained header blocks bypass maxSessionMemory limits (remote memory-exhaustion DoS, CVE-2026-56846), a re-entrant heap-use-after-free in the bundled nghttp2 library (crash/potential RCE, CVE-2026-56848), and a radix-tree prefix boundary flaw in the Permission Model that over-grants filesystem read/write access beyond the configured --permission allowlist (CVE-2026-58043, CVSS 7.5). Five MEDIUM and three LOW severity issues covering mTLS identity reuse, TLS hostname-verification bypass, SQLite prepared-statement replay, DNS resolver crashes, zlib crashes, and Permission Model write-outside-allowlist bugs were also patched; no public PoC or confirmed in-the-wild exploitation was reported for any of the 11 at release time.
On 2026-07-29 the Node.js Security Release Working Group published coordinated security releases for all three active release lines — v22.23.2 (LTS 'Jod'), v24.18.1 (LTS), and v26.5.1 (Current) — fixing 11 CVEs. The releases also bumped llhttp to 9.4.3 across all three lines and undici to 8.9.0 (v26.x) / 7.29.0 (v24.x) / 6.28.0 (v22.x). v22.23.2 ships 10 of the 11 fixes; CVE-2026-58041 (node:sqlite) does not apply to the 22.x line. The release itself slipped twice from its original target: the Working Group pushed it from ~2026-07-27 to 2026-07-28 for additional testing/validation, then again from 2026-07-28 to the actual 2026-07-29 ship date due to release-pipeline infrastructure issues (per digitalapplied.com's release-timeline analysis). NVD confirms the affected-version ceiling precisely: Node.js main, 22.23.1 and earlier, 24.18.0 and earlier, and 26.5.0 and earlier are vulnerable to CVE-2026-58043.
The three HIGH-severity issues center on the HTTP/2 implementation and the Permission Model sandbox. CVE-2026-56846 (reported by leduckhuong, fixed by Matteo Collina, commit 'retain header memory in session accounting') lets an attacker send crafted HTTP/2 traffic whose retained header blocks evade the configured maxSessionMemory limit, exhausting server memory and causing denial of service. CVE-2026-56848 (reported by hahahkim, fixed by Matteo Collina, commit 'defer rst stream while in scope') is a heap-use-after-free triggered when nghttp2_session_mem_send() executes re-entrantly while nghttp2_session_mem_recv() is still processing incoming data — independent analysis (digitalapplied.com) characterizes this as a crash/RCE-class memory-safety bug in a network-facing parser. CVE-2026-58043 (reported by sy2n0, fixed by RafaelGSS, commit 'avoid granting radix split nodes') is a boundary-handling flaw in the radix-tree structure backing the --permission flag's path-matching logic: code already permitted access to one filesystem path can abuse the boundary handling to read from or write to paths outside the intended --allow-fs-read/--allow-fs-write allowlist. This is the only one of the three HIGH CVEs with a public numeric score at release time: CVSS 7.5 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N, CWE-284 Improper Access Control), per NVD/HackerOne.
The five MEDIUM-severity issues: CVE-2026-56850 (reported by yottt, fixed by RafaelGSS) — the HTTPS Agent reuses TLS client identities across requests presenting different PFX certificates because of object-array agent-key collisions. CVE-2026-58040 (reported by vnyuh, fixed by Matteo Collina) — an incomplete fix for the earlier CVE-2026-48934 still allows TLS session reuse to skip hostname verification across differing security policies. CVE-2026-58041 (reported by cantina-security, fixed by Matteo Collina, nodejs-private/node-private PR #896) — node:sqlite's StatementSyncIterator objects, created through DatabaseSync#createTagStore(), are not invalidated on statement reset/rebind because the SQLTagStore cache resets statements by calling sqlite3_reset() directly rather than going through the iterator-invalidation path, so a stale iterator can replay a cached prepared statement and re-execute writes with new bound parameters — a data-integrity risk (unintended re-execution of INSERT/UPDATE/DELETE) rather than pure disclosure. CVE-2026-58042 (reported by cantina-security, fixed by RafaelGSS) — dns.resolveAny() can abort when a DNS response contains more than 256 A records, enabling a repeatable crash-based DoS. CVE-2026-58045 (reported by byvini, fixed by RafaelGSS) — a spoofed TypedArray.byteLength triggers a reachable assertion inside node:zlib's synchronous APIs, crashing the process.
The three LOW-severity issues are all further Permission Model boundary gaps plus an HTTP parser issue: CVE-2026-56847 (reported by 0xoroot, fixed by RafaelGSS) — trace_events.createTracing().enable() can write trace logs outside the --allow-fs-write allowlist. CVE-2026-58039 (reported by sinan-polat, fixed by RafaelGSS) — process.report can write or overwrite files outside the --allow-fs-write allowlist. CVE-2026-58044 (reported by yushengchen, fixed by Matteo Collina) — headers beyond maxHeadersCount are silently dropped from the visible request object (hiding framing-relevant headers such as Content-Length) while still being processed internally, creating an HTTP request-smuggling risk for front-end/back-end proxy chains that inspect only the visible headers.
No CVE in this release is listed in the CISA Known Exploited Vulnerabilities catalog and no public PoC was located; status is PATCHED for all 11 given the fixed versions are already released. Because three separate boundary-handling CVEs (58043, 56847, 58039) landed against the Permission Model in a single release, and CVE-2026-58040 is an incomplete fix for a prior CVE, the feature and the HTTPS Agent's session-reuse path both warrant continued scrutiny beyond just applying this patch.
MITRE ATT&CK techniques used in TL-2026-1807
Collection
T1005 Data from Local System; T1074 Data Staged
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation; T1548 Abuse Elevation Control Mechanism
Discovery
T1082 System Information Discovery; T1518 Software Discovery
Initial Access
T1190 Exploit Public-Facing Application
Lateral Movement
T1210 Exploitation of Remote Services
Defense Evasion
T1211 Exploitation for Stealth
defense-impairment
T1222 File and Directory Permissions Modification; T1685 Disable or Modify Tools
Impact
T1499 Endpoint Denial of Service; T1565 Data Manipulation
Credential Access
Resource Development
Reconnaissance
Affected products and versions in Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1
- OpenJS Foundation / Node.js Project — Node.js (v22.x 'Jod' LTS)
Vulnerable versions: <22.23.2
Fixed in: 22.23.2 - OpenJS Foundation / Node.js Project — Node.js (v24.x LTS)
Vulnerable versions: <24.18.1
Fixed in: 24.18.1 - OpenJS Foundation / Node.js Project — Node.js (v26.x Current)
Vulnerable versions: <26.5.1
Fixed in: 26.5.1
Remediation for Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1
Patches
- Node.js v22.23.2 (LTS 'Jod') — 10 of 11 CVEs fixed (CVE-2026-58041 not applicable to 22.x)
- Node.js v24.18.1 (LTS) — all 11 CVEs fixed
- Node.js v26.5.1 (Current) — all 11 CVEs fixed
Immediate actions
- Upgrade to Node.js v22.23.2, v24.18.1, or v26.5.1 (or later) on the corresponding release line immediately, prioritizing internet-facing HTTP/2 servers exposed to CVE-2026-56846 and CVE-2026-56848.
- For any process launched with --permission, audit --allow-fs-read/--allow-fs-write allowlist paths for unintended radix-tree boundary over-grants until patched (CVE-2026-58043).
- Review reverse-proxy / load-balancer configurations for HTTP request-smuggling exposure (Content-Length vs Transfer-Encoding handling across the maxHeadersCount boundary) pending confirmation the CVE-2026-58044 fix is deployed everywhere in the request path.
Workarounds
- Where immediate upgrade is not possible, tighten maxSessionMemory and HTTP/2 concurrent-stream limits to reduce the CVE-2026-56846 blast radius.
- Restrict or disable trace_events and process.report usage in --permission-restricted processes until patched, closing the CVE-2026-56847 / CVE-2026-58039 write-outside-allowlist gaps.
- Terminate TLS at a proxy that independently enforces hostname verification, rather than relying on Node's HTTPS Agent session-reuse path, until CVE-2026-58040 is patched.
Longer-term hardening
- Adopt automated Node.js LTS patch-tracking (Node.js Security WG mailing list/RSS) given all three active release lines (22.x/24.x/26.x) received independent fixes in this release.
- Do not rely solely on the Node.js --permission Permission Model as a hard security boundary for untrusted or AI-generated code; pair it with OS-level sandboxing (containers, seccomp, gVisor) given three separate boundary-handling CVEs (58043, 56847, 58039) landed in this single release.
- Re-validate mTLS client-certificate handling and TLS session-reuse code paths after upgrading, since CVE-2026-58040 is an incomplete fix for the earlier CVE-2026-48934.
CVEs associated with Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1
CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-56850, CVE-2026-58039, CVE-2026-58040, CVE-2026-58041, CVE-2026-58042, CVE-2026-58043, CVE-2026-58044, CVE-2026-58045, CVE-2026-48934
Weaknesses (CWE) in Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1
CWE-284, CWE-400, CWE-416, CWE-295, CWE-297, CWE-672, CWE-20, CWE-617, CWE-668, CWE-444
Timeline of Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1
- Node.js Security Release Working Group announces the coordinated security release, originally targeted around July 27, 2026, is delayed to July 28 for additional testing and validation of the 11 fixes.
- The Working Group delays the release a second time, from July 28 to July 29, 2026, citing infrastructure issues with the release pipeline.
- Node.js v26.5.1 ships fixes for all 11 CVEs alongside llhttp 9.4.3 and undici 8.9.0.
- Node.js v24.18.1 ships fixes for all 11 CVEs, including CVE-2026-58041 (node:sqlite StatementSyncIterator stale-iterator write replay), alongside llhttp 9.4.3 and undici 7.29.0.
- Node.js v22.23.2 ships fixes for 10 of the 11 CVEs (all except CVE-2026-58041, since node:sqlite is not affected on the 22.x line) alongside llhttp 9.4.3 and undici 6.28.0 dependency bumps.
- Node.js Security Release Working Group publishes coordinated security releases v22.23.2 (LTS 'Jod'), v24.18.1 (LTS), and v26.5.1 (Current), fixing 11 CVEs across all three active release lines.
- HKCERT (Hong Kong Computer Emergency Response Team Coordination Centre) issues a security bulletin covering the Node.js multiple-vulnerabilities release.
- CyberPress and Cybersecurity News publish parallel technical coverage of the 11-CVE release, both noting that only one of the three HIGH-severity CVEs (CVE-2026-58043) had a numeric CVSS score in a public vulnerability database at release time.
- GBHackers publishes 'Node.js Patches 11 Security Flaws', the source-feed article that triggered TL-Intel-Harness hunt ingestion for TL-2026-1807.
- NVD last-modifies the CVE-2026-58043 entry (published 2026-07-30); it remains the only one of the three HIGH-severity CVEs with a published CVSS score at this point (7.5, CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N, CWE-284), while CVE-2026-56846 and CVE-2026-56848 stay unscored/reserved in NVD.
Sources cited for Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1
- Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1
- Node.js Patches 11 Security Flaws Enabling Memory Exhaustion, File Access and Request Smuggling
- Node.js Fixes 11 Security Flaws That Can Crash Servers and Break Filesystem Restrictions
- Node.js July 2026 Security Releases: What Actually Shipped
- Node.js — Wednesday, July 29, 2026 Security Releases
- Node.js v22.23.2 (LTS) Release Notes
- Node.js v24.18.1 (LTS) Release Notes
- Node.js v26.5.1 (Current) Release Notes
- CVE-2026-58043 Detail (NVD)
- HKCERT Security Bulletin: Node.js Multiple Vulnerabilities
- nodejs-private/node-private PR #896 (CVE-2026-58041 fix reference)
Detection coverage for TL-2026-1807
As of 2026-08-01, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1807 across Splunk SPL, Microsoft KQL and Sigma, covering 34 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.