CVE-2026-48933
Summary
| CVE | CVE-2026-48933 |
|---|---|
| State | PUBLISHED |
| Assigner | hackerone |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-26 02:16:52 UTC |
| Updated | 2026-07-21 12:18:52 UTC |
| Description | A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS: 0.028060000 probability, percentile 0.849450000 (date 2026-07-21)
Problem Types: CWE-190 | CWE-770 | CWE-190 CWE-190 Integer Overflow | CWE-770 Allocation of Resources Without Limits or Throttling
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | CVSS | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.1 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.0 | [email protected] | Secondary | 7.5 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| 3.0 | CNA | DECLARED | 7.5 | HIGH | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v3.0 Breakdown
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Nodejs | Node | affected 22.22.3 22.22.3 semver | Not specified |
| CNA | Nodejs | Node | affected 24.16.0 24.16.0 semver | Not specified |
| CNA | Nodejs | Node | affected 26.3.0 26.3.0 semver | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10 | unaffected 1:24.18.0-1.el10_2 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10 | unaffected 1:22.23.1-2.el10_2 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | unaffected 1:22.23.1-2.el10_0 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | unaffected 8100020260630152626.6d880403 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | unaffected 8100020260703140402.6d880403 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | unaffected 9080020260626074955.rhel9 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | unaffected 9080020260626075442.rhel9 * rpm | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | unaffected 22.23.1-1.hum1 * rpm | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | unaffected 24.18.0-0.1.hum1 * rpm | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | unaffected 26.4.0-1.2.hum1 * rpm | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | unaffected 25.9.0-1.1.hum1 * rpm | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | unaffected 20.20.2-1.hum1 * rpm | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2026:7378 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:35891 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:35842 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:41947 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| nodejs.org/en/blog/vulnerability/june-2026-security-releases | [email protected] | nodejs.org | Patch, Vendor Advisory |
| bugzilla.redhat.com/show_bug.cgi | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2026:28727 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.json | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | security.access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:35892 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:35841 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:39246 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:39868 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:9455 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:29012 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:30172 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2026-48933 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-06-26T02:01:39.107Z | Reported to Red Hat. |
| ADP | 2026-06-26T01:14:36.823Z | Made public. |
Solutions
ADP: RHSA-2026:39246: Red Hat Enterprise Linux AppStream EUS (v. 10.0)
ADP: RHSA-2026:35842: Red Hat Enterprise Linux AppStream (v. 10)
ADP: RHSA-2026:35841: Red Hat Enterprise Linux AppStream (v. 10)
ADP: RHSA-2026:41947: Red Hat Enterprise Linux AppStream (v. 8)
ADP: RHSA-2026:39868: Red Hat Enterprise Linux AppStream (v. 8)
ADP: RHSA-2026:35892: Red Hat Enterprise Linux AppStream (v. 9)
ADP: RHSA-2026:35891: Red Hat Enterprise Linux AppStream (v. 9)
ADP: RHSA-2026:9455: Red Hat Hardened Images
ADP: RHSA-2026:28727: Red Hat Hardened Images
ADP: RHSA-2026:29012: Red Hat Hardened Images
ADP: RHSA-2026:7378: Red Hat Hardened Images
ADP: RHSA-2026:30172: Red Hat Hardened Images
Workarounds
ADP: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.