Repository navigation
CVE-2026-48932 commit #66630
Description
Activity
According to https://hackerone.com/reports/3564941
updated CVE reference to CVE-2026-48932 was followed by
updated CVE reference to CVE-2026-58044CVE-2026-58044 is listed as resolved in security releases, as documented in the release notes:
You can also find the information under https://nodejs.org/en/blog/release, for example
- addedquestionIssues asking questions about Node.js.Issues asking questions about Node.js.securityIssues and PRs related to security.Issues and PRs related to security.
on Oct 9, 2026 Could you simply in this case that the fix of GHSA-6hff-9f4h-85xm fix GHSA-44cw-v76j-7fvv ?
We want to cross check
https://nvd.nist.gov/vuln/detail/cve-2026-48932 states that it affects Node.js <=22.22.3
https://nvd.nist.gov/vuln/detail/cve-2026-58044 states that it affects Node.js <=22.23.1Dear @MikeMcC399
As a distro we want to backport to EOL distrib thus we need exact commit fixing or to know if CVE are duplicate.
In this case could you confirm that commit this commit fix both CVE c8525ac
I've re-opened your issue in case the security team are able to provide you with the information you are looking for. The two CVE reports specify different affected versions, and there are no specific changelog entries mentioning https://nvd.nist.gov/vuln/detail/cve-2026-48932.
Version
22
Platform
Subsystem
none
What steps will reproduce the bug?
On debian side we could not found the commit on your tree fixing CVE-2026-48932...
Is it the same then fix of CVE-2026-58044
c8525ac
How often does it reproduce? Is there a required condition?
always
What is the expected behavior? Why is that the expected behavior?
document the commit that fix CVE
What do you see instead?
not applicatble
Additional information
No response