VDB
GCVE-110-MAGEIA-2026-257
GCVE-110-MAGEIA-2026-257
Advisory Published
lib,test: redact proxy credentials in tunnel errors. (CVE-2026-48615)
permission: handle process.chdir on writereport. (CVE-2026-48617)
tls: normalize hostname for server identity checks. (CVE-2026-48618)
http2: cap originSet size to prevent unbounded memory growth.
(CVE-2026-48619)
tls: fix case-sensitive SNI context matching. (CVE-2026-48928)
dns,net: reject hostnames with embedded NUL bytes. (CVE-2026-48930)
http: fix response queue poisoning in http.Agent. (CVE-2026-48931)
crypto: guard WebCrypto cipher output length. (CVE-2026-48933)
tls: bind reusable sessions to authenticated host. (CVE-2026-48934)
permission: disable FileHandle utimes with permission model.
(CVE-2026-48935)
deps: fix integration issues with the latest nghttp2. (CVE-2026-48937)
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | nodejs | 0 (affected), 22.23.1-2.mga10 (unaffected) | — |
| Mageia | nodejs | 0 (affected), 22.23.1-2.mga9 (unaffected) | — |
Browse GCVE Records
67,723 records in the GCVE database · Updated August 13, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.