# Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1 (HTTP/2 DoS, Permission Model Bypass, TLS/mTLS Issues)

> Node.js released v22.23.2, v24.18.1, and v26.5.1 on 2026-07-29 fixing 11 CVEs, including three HIGH-severity issues: an HTTP/2 flaw letting retained header blocks bypass maxSessionMemory limits (remote memory-exhaustion DoS, CVE-2026-56846), a re-entrant heap-use-after-free in the bundled nghttp2 library (crash/potential RCE, CVE-2026-56848), and a radix-tree prefix boundary flaw in the Permission Model that over-grants filesystem read/write access beyond the configured --permission allowlist (CVE-2026-58043, CVSS 7.5). Five MEDIUM and three LOW severity issues covering mTLS identity reuse, TLS hostname-verification bypass, SQLite prepared-statement replay, DNS resolver crashes, zlib crashes, and Permission Model write-outside-allowlist bugs were also patched; no public PoC or confirmed in-the-wild exploitation was reported for any of the 11 at release time.

- **Published:** 2026-08-01T00:00:00Z
- **Last reviewed:** 2026-08-01T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1807
- **ID:** TL-2026-1807
- **Severity:** HIGH (CVSS 7.5)
- **Category:** VULNERABILITY
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 34 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-56850, CVE-2026-58039, CVE-2026-58040, CVE-2026-58041, CVE-2026-58042, CVE-2026-58043, CVE-2026-58044, CVE-2026-58045, CVE-2026-48934

## Description

On 2026-07-29 the Node.js Security Release Working Group published coordinated security releases for all three active release lines — v22.23.2 (LTS 'Jod'), v24.18.1 (LTS), and v26.5.1 (Current) — fixing 11 CVEs. The releases also bumped llhttp to 9.4.3 across all three lines and undici to 8.9.0 (v26.x) / 7.29.0 (v24.x) / 6.28.0 (v22.x). v22.23.2 ships 10 of the 11 fixes; CVE-2026-58041 (node:sqlite) does not apply to the 22.x line. The release itself slipped twice from its original target: the Working Group pushed it from ~2026-07-27 to 2026-07-28 for additional testing/validation, then again from 2026-07-28 to the actual 2026-07-29 ship date due to release-pipeline infrastructure issues (per digitalapplied.com's release-timeline analysis). NVD confirms the affected-version ceiling precisely: Node.js main, 22.23.1 and earlier, 24.18.0 and earlier, and 26.5.0 and earlier are vulnerable to CVE-2026-58043.

The three HIGH-severity issues center on the HTTP/2 implementation and the Permission Model sandbox. CVE-2026-56846 (reported by leduckhuong, fixed by Matteo Collina, commit 'retain header memory in session accounting') lets an attacker send crafted HTTP/2 traffic whose retained header blocks evade the configured maxSessionMemory limit, exhausting server memory and causing denial of service. CVE-2026-56848 (reported by hahahkim, fixed by Matteo Collina, commit 'defer rst stream while in scope') is a heap-use-after-free triggered when nghttp2_session_mem_send() executes re-entrantly while nghttp2_session_mem_recv() is still processing incoming data — independent analysis (digitalapplied.com) characterizes this as a crash/RCE-class memory-safety bug in a network-facing parser. CVE-2026-58043 (reported by sy2n0, fixed by RafaelGSS, commit 'avoid granting radix split nodes') is a boundary-handling flaw in the radix-tree structure backing the --permission flag's path-matching logic: code already permitted access to one filesystem path can abuse the boundary handling to read from or write to paths outside the intended --allow-fs-read/--allow-fs-write allowlist. This is the only one of the three HIGH CVEs with a public numeric score at release time: CVSS 7.5 (CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N, CWE-284 Improper Access Control), per NVD/HackerOne.

The five MEDIUM-severity issues: CVE-2026-56850 (reported by yottt, fixed by RafaelGSS) — the HTTPS Agent reuses TLS client identities across requests presenting different PFX certificates because of object-array agent-key collisions. CVE-2026-58040 (reported by vnyuh, fixed by Matteo Collina) — an incomplete fix for the earlier CVE-2026-48934 still allows TLS session reuse to skip hostname verification across differing security policies. CVE-2026-58041 (reported by cantina-security, fixed by Matteo Collina, nodejs-private/node-private PR #896) — node:sqlite's StatementSyncIterator objects, created through DatabaseSync#createTagStore(), are not invalidated on statement reset/rebind because the SQLTagStore cache resets statements by calling sqlite3_reset() directly rather than going through the iterator-invalidation path, so a stale iterator can replay a cached prepared statement and re-execute writes with new bound parameters — a data-integrity risk (unintended re-execution of INSERT/UPDATE/DELETE) rather than pure disclosure. CVE-2026-58042 (reported by cantina-security, fixed by RafaelGSS) — dns.resolveAny() can abort when a DNS response contains more than 256 A records, enabling a repeatable crash-based DoS. CVE-2026-58045 (reported by byvini, fixed by RafaelGSS) — a spoofed TypedArray.byteLength triggers a reachable assertion inside node:zlib's synchronous APIs, crashing the process.

The three LOW-severity issues are all further Permission Model boundary gaps plus an HTTP parser issue: CVE-2026-56847 (reported by 0xoroot, fixed by RafaelGSS) — trace_events.createTracing().enable() can write trace logs outside the --allow-fs-write allowlist. CVE-2026-58039 (reported by sinan-polat, fixed by RafaelGSS) — process.report can write or overwrite files outside the --allow-fs-write allowlist. CVE-2026-58044 (reported by yushengchen, fixed by Matteo Collina) — headers beyond maxHeadersCount are silently dropped from the visible request object (hiding framing-relevant headers such as Content-Length) while still being processed internally, creating an HTTP request-smuggling risk for front-end/back-end proxy chains that inspect only the visible headers.

No CVE in this release is listed in the CISA Known Exploited Vulnerabilities catalog and no public PoC was located; status is PATCHED for all 11 given the fixed versions are already released. Because three separate boundary-handling CVEs (58043, 56847, 58039) landed against the Permission Model in a single release, and CVE-2026-58040 is an incomplete fix for a prior CVE, the feature and the HTTPS Agent's session-reuse path both warrant continued scrutiny beyond just applying this patch.

## MITRE ATT&CK

- T1592 Gather Victim Host Information
- T1595 Active Scanning
- T1588 Obtain Capabilities
- T1518 Software Discovery
- T1082 System Information Discovery
- T1190 Exploit Public-Facing Application
- T1059 Command and Scripting Interpreter
- T1210 Exploitation of Remote Services
- T1548 Abuse Elevation Control Mechanism
- T1068 Exploitation for Privilege Escalation
- T1222 File and Directory Permissions Modification
- T1685 Disable or Modify Tools
- T1211 Exploitation for Stealth
- T1557 Adversary-in-the-Middle
- T1005 Data from Local System
- T1074 Data Staged
- T1499 Endpoint Denial of Service
- T1565 Data Manipulation

## Sources

- [Node.js Patches 11 Security Flaws Across v22.23.2, v24.18.1, v26.5.1](https://gbhackers.com/node-js-patches-11-security-flaws/)
- [Node.js Patches 11 Security Flaws Enabling Memory Exhaustion, File Access and Request Smuggling](https://cyberpress.org/node-js-patches-11-security-flaws/)
- [Node.js Fixes 11 Security Flaws That Can Crash Servers and Break Filesystem Restrictions](https://cybersecuritynews.com/node-js-fixes-11-security-flaws/)
- [Node.js July 2026 Security Releases: What Actually Shipped](https://www.digitalapplied.com/blog/nodejs-july-2026-security-releases-shipped)
- [Node.js — Wednesday, July 29, 2026 Security Releases](https://nodejs.org/en/blog/vulnerability/july-2026-security-releases)
- [Node.js v22.23.2 (LTS) Release Notes](https://nodejs.org/en/blog/release/v22.23.2)
- [Node.js v24.18.1 (LTS) Release Notes](https://nodejs.org/en/blog/release/v24.18.1)
- [Node.js v26.5.1 (Current) Release Notes](https://nodejs.org/en/blog/release/v26.5.1)
- [CVE-2026-58043 Detail (NVD)](https://nvd.nist.gov/vuln/detail/CVE-2026-58043)
- [HKCERT Security Bulletin: Node.js Multiple Vulnerabilities](https://www.hkcert.org/security-bulletin/node-js-multiple-vulnerabilities_20260730)
- [nodejs-private/node-private PR #896 (CVE-2026-58041 fix reference)](https://github.com/nodejs-private/node-private/pull/896)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1807
