Description
There are packages installed that are affected by multiple vulnerabilities referenced in the following CVEs:
- A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority
rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported
release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. (CVE-2026-48930)
- A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error
messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling
paths and captured by logs, diagnostics, or other error consumers. This vulnerability affects all
supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. (CVE-2026-48615)
- A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path
Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under
affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js
24**, and **Node.js 26**. (CVE-2026-48617)
- A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls
wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can
lead to confidentiality impact or bypass of the intended security boundary under affected configurations.
This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js
26**. (CVE-2026-48618)
- A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could
lead to an Out of Memory error on the client. This vulnerability affects all supported release lines:
**Node.js 22**, **Node.js 24**, and **Node.js 26**. (CVE-2026-48619)
Solution
Update the nodejs library and its related packages to version 24.17.0-r0 or later.
Plugin Details
Supported Sensors: Agentless Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Vulnerability Information
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 6/18/2026
Reference Information
CVE: CVE-2026-48615, CVE-2026-48617, CVE-2026-48618, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48931, CVE-2026-48933, CVE-2026-48934, CVE-2026-48935, CVE-2026-48937