CVE Vulnerabilities

CVE-2026-56847

Excessive Use of Unconditional Branching

Published: Jul 30, 2026 | Modified: Aug 25, 2026
CVSS 3.x
6.1
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
3.3 LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A flaw in Node.js Permission Model enforcement allows trace_events.createTracing().enable() Writes Trace Logs Outside --allow-fs-write.

This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.

This vulnerability affects Node.js 22.x, 24.x, and 26.x.

Weakness

The code uses too many unconditional branches (such as “goto”).

Affected Software

NameVendorStart VersionEnd Version
Node.jsNodejs22.0 (including)22.23.1 (including)
Node.jsNodejs24.0.0 (including)24.18.0 (including)
Node.jsNodejs26.0.0 (including)26.5.0 (including)
Red Hat Hardened ImagesRedHatnodejs26-main-26.5.1-1.5.hum1*
Red Hat Hardened ImagesRedHatnodejs22-main-22.23.2-2.3.hum1*
Red Hat Hardened ImagesRedHatnodejs24-main-24.18.1-0.1.hum1*

References