Node.js 22.x < 22.23.2 / 24.x < 24.18.1 / 26.x < 26.5.1 Multiple Vulnerabilities (Wednesday, July 29, 2026 Security Releases)
39003
22 September 2026
22 September 2026
CLOSED
LOW
Varies
CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-56850, CVE-2026-58039, CVE-2026-58040, CVE-2026-58041, CVE-2026-58042, CVE-2026-58043, CVE-2026-58044, CVE-2026-58045
|
Brocade Security Advisory ID |
BSA-2026-3899 |
|
Component |
Node.js |
|
|
|
Summary
The version of Node.js used within the Brocade SANnav is not affected, but does contain the vulnerable code for the following vulnerabilities as referenced in the Wednesday, July 29, 2026 Security Releases advisory.
- A flaw in Node.js allows a spoofed TypedArray byteLength to trigger a reachable assertion in the synchronous node:zlib APIs, causing the process to crash. Repeated exploitation of this condition can result in a denial of service. Impact: Thank you, to byvini for reporting this vulnerability and thank you RafaelGSS for fixing it. (CVE-2026-58045)
- A flaw in Node.js HTTP/2 handling can let retained header blocks evade maxSessionMemory limits and cause remote memory exhaustion. Impact: Thank you, to leduckhuong for reporting this vulnerability and thank you mcollina for fixing it. (CVE-2026-56846)
- A flaw in Node.js HTTP/2 handling allows nghttp2_session_mem_send() to be called re-entrantly while nghttp2_session_mem_recv() is executing, resulting in a heap-use-after-free. Impact: Thank you, to hahahkim for reporting this vulnerability and thank you mcollina for fixing it. (CVE-2026-56848)
- A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under --permission, an attacker who is granted access to one path can abuse radix-tree prefix boundary handling to read from or write to paths outside the intended filesystem allowlist. Impact: Thank you, to sy2n0 for reporting this vulnerability and thank you RafaelGSS for fixing it. (CVE-2026-58043)
- A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates.
Impact: Thank you, to yottt for reporting this vulnerability and thank you RafaelGSS for fixing it.
(CVE-2026-56850)
Products Affected
- No Brocade products are affected
Products Not Affected
- Brocade Fabric OS
[VEX Justification: Component_not_present] - Brocade SANnav
[VEX Justification: Vulnerable_code_cannot_be_contolled_by_adversary] - Brocade ASCG
[VEX Justification: Vulnerable_code_not_present]
Solution
- While not exploitable, a security update is provided in Brocade SANnav 3.0.1a
Revision History
|
Version |
Change |
Date |
|
1.0 |
Initial Publication |
September 22, 2026 |
Disclaimer
THIS DOCUMENT IS PROVIDED ON AN AS-IS BASIS SOLELY FOR INFORMATIONAL PURPOSES AND DOES NOT IMPLY ANY KIND OF GUARANTY OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE. YOUR USE OF THE INFORMATION CONTAINED HEREIN IS AT YOUR OWN RISK. ALL INFORMATION PROVIDED HEREIN IS BASED ON BROCADE'S CURRENT KNOWLEDGE AND UNDERSTANDING OF THE VULNERABILITY AND IMPACT TO BROCADE HARDWARE AND SOFTWARE PRODUCTS. BROCADE RESERVES THE RIGHT TO CHANGE OR UPDATE THIS DOCUMENT AT ANY TIME.