A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
{ "binaries": [ { "binary_name": "libnode109", "binary_version": "18.19.1+dfsg-6ubuntu5" }, { "binary_name": "nodejs", "binary_version": "18.19.1+dfsg-6ubuntu5" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-48931.json"
{ "binaries": [ { "binary_name": "libnode115", "binary_version": "20.19.4+dfsg-1" }, { "binary_name": "nodejs", "binary_version": "20.19.4+dfsg-1" } ] }
{ "binaries": [ { "binary_name": "libnode127", "binary_version": "22.22.1+dfsg+~cs22.19.15-1ubuntu1" }, { "binary_name": "nodejs", "binary_version": "22.22.1+dfsg+~cs22.19.15-1ubuntu1" } ] }
{ "binaries": [ { "binary_name": "nodejs", "binary_version": "0.10.25~dfsg2-2ubuntu1.2+esm2" }, { "binary_name": "nodejs-legacy", "binary_version": "0.10.25~dfsg2-2ubuntu1.2+esm2" } ] }
{ "binaries": [ { "binary_name": "nodejs", "binary_version": "4.2.6~dfsg-1ubuntu4.2+esm3" }, { "binary_name": "nodejs-legacy", "binary_version": "4.2.6~dfsg-1ubuntu4.2+esm3" } ] }
{ "binaries": [ { "binary_name": "nodejs", "binary_version": "8.10.0~dfsg-2ubuntu0.4+esm6" } ] }
{ "binaries": [ { "binary_name": "libnode64", "binary_version": "10.19.0~dfsg-3ubuntu1.6+esm2" }, { "binary_name": "nodejs", "binary_version": "10.19.0~dfsg-3ubuntu1.6+esm2" } ] }
{ "binaries": [ { "binary_name": "libnode72", "binary_version": "12.22.9~dfsg-1ubuntu3.6+esm2" }, { "binary_name": "nodejs", "binary_version": "12.22.9~dfsg-1ubuntu3.6+esm2" } ] }