PT-2026-73399 · Bitnami · Node

Published

2026-08-17

·

Updated

2026-08-17

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and rebound with new parameters. SQLTagStore resets cached statements using sqlite3 reset() directly, bypassing the iterator invalidation mechanism introduced for StatementSync in recent releases
This vulnerability affects Node.js 22.x, 24.x, and 26.x.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BIT-NODE-2026-58041

Affected Products

Node