
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-75803 is a cryptographic vulnerability in Node.js where use of EVP_Cipher() can allow AEAD (Authenticated Encryption with Associated Data) message forgeries when the ciphertext is empty. The CVE is currently in Reserved status, meaning full technical details have not yet been publicly disclosed. It has been estimated as HIGH severity by Feedly's threat intelligence system, and was first detected by Nessus (plugin 338398) (Tenable). The vulnerability was inserted into Feedly's tracking system on 2026-08-20, with limited official information available at this time.
The vulnerability stems from improper handling of empty ciphertext inputs when using OpenSSL's EVP_Cipher() API within Node.js, which can cause AEAD authentication tag verification to be bypassed or forged (CWE classification not yet officially assigned, but likely related to CWE-327: Use of a Broken or Risky Cryptographic Algorithm or CWE-347: Improper Verification of Cryptographic Signature). AEAD modes (such as AES-GCM) are designed to provide both confidentiality and integrity guarantees; a forgery vulnerability means an attacker may be able to craft or manipulate messages that pass authentication checks without possessing the correct key. The specific attack vector and preconditions — such as whether attacker-controlled input reaches the vulnerable code path — have not been fully disclosed, as the CVE remains in Reserved status (Tenable, Radar Offseq).
If successfully exploited, this vulnerability could allow an attacker to forge authenticated messages in applications relying on Node.js AEAD encryption, undermining the integrity guarantees of encrypted communications. This could lead to unauthorized data manipulation, bypass of message authentication checks, and potential confidentiality breaches depending on how the affected cryptographic operations are used in the target application. Applications using Node.js cryptographic APIs with AEAD ciphers (e.g., AES-GCM) and processing empty or attacker-controlled ciphertexts are most at risk (Radar Offseq).
As of the time of this report, CVE-2026-75803 is in Reserved status with no confirmed public exploit code, proof-of-concept, or in-the-wild exploitation reported. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No EPSS score or threat actor attribution is currently available. Feedly's assessment characterizes this as an "early-stage threat with insufficient data for impact assessment" and recommends monitoring for official disclosure and vendor guidance (Tenable).
No official patch or vendor advisory has been published at this time, as the CVE remains in Reserved status. Organizations using Node.js should monitor the official Node.js security advisories and the CVE database for updates upon full disclosure. As a precautionary measure, review application code that uses Node.js cryptographic APIs with AEAD modes (particularly EVP_Cipher() or equivalent wrappers) and ensure that empty ciphertext inputs are explicitly rejected at the application layer. Keeping Node.js updated to the latest stable release is strongly recommended once a patched version is identified (Tenable, Vulners/Ubuntu).
Coverage of CVE-2026-75803 is currently limited given its Reserved status. Tenable has published a Nessus detection plugin (338398), and threat intelligence aggregators such as Radar Offseq and Vulners have begun tracking the vulnerability. No notable researcher commentary, vendor statements, or significant media coverage has emerged at this stage (Radar Offseq, Vulners/Ubuntu).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."