CVE detail
CVE-2026-48933
A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 28.3 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
16 source links · newest first
- https://access.redhat.com/errata/RHSA-2026:41947access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 26, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:39868access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 26, 2026, 2:16 AM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comJun 26, 2026, 2:16 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2493331bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJun 26, 2026, 2:16 AM - https://access.redhat.com/security/cve/CVE-2026-48933access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 26, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:9455access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 26, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:7378access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 26, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:39246access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 26, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:35892access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 26, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:35891access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 26, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:35842access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 26, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:35841access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 26, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:30172access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 26, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:29012access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 26, 2026, 2:16 AM - https://access.redhat.com/errata/RHSA-2026:28727access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 26, 2026, 2:16 AM No excerpt available.
Vendor Advisorynodejs.orgJun 26, 2026, 2:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-55254CVSS 4.8 · Medium
NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator implementation in src/NCalc.Core/Helpers/MathHelper.cs permits specially crafted…
- CVE-2026-44216CVSS 5.9 · Medium
Wasmtime is a runtime for WebAssembly. From 30.0.0 to 36.0.8, 43.0.2, and 44.0.1, Wasmtime's allocation logic for a WebAssembly table contained checked arithmetic which panicked o…
- CVE-2025-14299CVSS 7.1 · High
The HTTPS server on Tapo C200 V3 does not properly validate the Content-Length header, which can lead to an integer overflow. An unauthenticated attacker on the same local network…
- CVE-2020-10531CVSS 8.8 · High
An issue was discovered in International Components for Unicode (ICU) for C/C++ through 66.1. An integer overflow, leading to a heap-based buffer overflow, exists in the UnicodeSt…
- CVE-2019-9518CVSS 7.5 · High
Some HTTP/2 implementations are vulnerable to a flood of empty frames, potentially leading to a denial of service. The attacker sends a stream of frames with an empty payload and…
- CVE-2019-9517CVSS 7.5 · High
Some HTTP/2 implementations are vulnerable to unconstrained interal data buffering, potentially leading to a denial of service. The attacker opens the HTTP/2 window so the peer ca…