Skip to content

CVE-2026-48932 commit #66630

Description

@bastien-roucaries

Version

22

Platform

linux

Subsystem

none

What steps will reproduce the bug?

On debian side we could not found the commit on your tree fixing CVE-2026-48932...

Is it the same then fix of CVE-2026-58044
c8525ac

How often does it reproduce? Is there a required condition?

always

What is the expected behavior? Why is that the expected behavior?

document the commit that fix CVE

What do you see instead?

not applicatble

Additional information

No response

Activity

  1. MikeMcC399 commented on Oct 9, 2026

    @MikeMcC399
    Contributor

    According to https://hackerone.com/reports/3564941
    updated CVE reference to CVE-2026-48932 was followed by
    updated CVE reference to CVE-2026-58044

    CVE-2026-58044 is listed as resolved in security releases, as documented in the release notes:

    You can also find the information under https://nodejs.org/en/blog/release, for example

  2. added
    questionIssues asking questions about Node.js.
    securityIssues and PRs related to security.
    on Oct 9, 2026
  3. bastien-roucaries commented on Oct 9, 2026

    @bastien-roucaries
    Author

    Could you simply in this case that the fix of GHSA-6hff-9f4h-85xm fix GHSA-44cw-v76j-7fvv ?

    We want to cross check

  4. MikeMcC399 commented on Oct 9, 2026

    @MikeMcC399
    Contributor

    https://nvd.nist.gov/vuln/detail/cve-2026-48932 states that it affects Node.js <=22.22.3
    https://nvd.nist.gov/vuln/detail/cve-2026-58044 states that it affects Node.js <=22.23.1

  5. bastien-roucaries commented on Oct 9, 2026

    @bastien-roucaries
    Author

    Dear @MikeMcC399

    As a distro we want to backport to EOL distrib thus we need exact commit fixing or to know if CVE are duplicate.

    In this case could you confirm that commit this commit fix both CVE c8525ac

  6. MikeMcC399 commented on Oct 10, 2026

    @MikeMcC399
    Contributor

    I've re-opened your issue in case the security team are able to provide you with the information you are looking for. The two CVE reports specify different affected versions, and there are no specific changelog entries mentioning https://nvd.nist.gov/vuln/detail/cve-2026-48932.

  7. jasnell commented on Oct 10, 2026

    @jasnell
    Member
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionIssues asking questions about Node.js.securityIssues and PRs related to security.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions