CVE-2026-56847

Aliases:ALPINE-CVE-2026-56847UBUNTU-CVE-2026-56847DEBIAN-CVE-2026-56847CGA-2jg9-h3r5-vmw6CGA-6jfv-h6wr-hwhvCGA-f5vf-f4cg-fr4hCGA-j345-m9mc-qmxvCGA-vw9c-7m4m-hrpgCGA-wwfq-rf37-5vw6
Analyzed
Published: 30 Jul 2026, 06:02
Last modified:30 Jul 2026, 12:35

Vulnerability Summary

Overall Risk (default)
low
24/100
CVSS Score
6.1 MEDIUM
v3.1 (nvd)
EPSS Score
0.16% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Jul 2026, 06:02
Published
Vulnerability first disclosed
30 Jul 2026, 12:35
Last Modified
Vulnerability information updated

Description

A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside `--allow-fs-write`. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

CVSS Metrics

  • v3.1MEDIUMScore: 6.1CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
  • v3.0LOWScore: 3.3CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

EPSS Trends

Current EPSS score: 0.16% Percentile: 5%

Techniques & Countermeasures

  • CWE-1119Excessive Use of Unconditional Branching

    The code uses too many unconditional branches (such as "goto").

Affected Systems

  • alpinenodejs

    < 22.23.2-r0 | < 22.23.2-r0 | < 24.18.1-r0 | < 24.18.1-r0

  • chainguardnodejs-20

    all

  • chainguardnodejs-22

    < 22.23.2-r0

  • chainguardnodejs-25

    all

  • wolfinodejs-20

    all

  • wolfinodejs-22

    < 22.23.2-r0

  • wolfinodejs-25

    all

  • debiannodejs

    all | all | < 24.19.0+dfsg+~cs24.13.3-1

  • ubuntunodejs

    all | all | all

  • nodejsnode

    26.5.0 | 24.18.0 | 22.23.1

  • nodejsnode.js

    ≥ 22.0, ≤ 22.23.1 | ≥ 24.0.0, ≤ 24.18.0 | ≥ 26.0.0, ≤ 26.5.0

References (8)