kapsl Index
Docs Releases

nodejs

1 tool · 4 release lines

Node.js runtime. Every tool here carries the same sandbox boundary.

Release lines we maintain · the project decides these

findings shown are the whole project at that line

Tag Resolves to Lifecycle Updated Findings What the tag promises
  • stable — floats, carries security updates
  • unstable — tracks pre-releases, may break
  • eol — frozen, upstream is done

Tools in this project · pick one to inspect

all share one boundary

Tool Capabilities Seccomp Findings Image Description
showing node from nodejs@latest → 26.8.0 stable nodejs@26 → 26.8.0 stable nodejs@24 → 24.20.0 stable nodejs@22 → 22.23.2 stable

Findings

H1M3L1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-33630 ↗ M c-ares CVE-2026-33630
CVE-2026-69184 ↗ M c-ares CVE-2026-69184
CVE-2026-69186 ↗ M c-ares CVE-2026-69186
CVE-2026-75803 ↗ L openssl CVE-2026-75803

1 further advisory matched this image and was assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex

These are the findings of nodejs, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Findings

H1M3L1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-33630 ↗ M c-ares CVE-2026-33630
CVE-2026-69184 ↗ M c-ares CVE-2026-69184
CVE-2026-69186 ↗ M c-ares CVE-2026-69186
CVE-2026-75803 ↗ L openssl CVE-2026-75803

1 further advisory matched this image and was assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex

These are the findings of nodejs, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Findings

H1M3L1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-33630 ↗ M c-ares CVE-2026-33630
CVE-2026-69184 ↗ M c-ares CVE-2026-69184
CVE-2026-69186 ↗ M c-ares CVE-2026-69186
CVE-2026-75803 ↗ L openssl CVE-2026-75803

1 further advisory matched this image and was assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex

These are the findings of nodejs, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Findings

H1M3L1

identical on amd64, arm64 — one table describes both

CVE Sev CVSS Affects Description
CVE-2026-14456 ↗ H 7.5 openssl Issue summary: When an OpenSSL QUIC server (Listener SSL object) processes valid QUIC Initial packets for unknown destination connection IDs, it can allocate and queue new incoming channels without enforcing any limit.
CVE-2026-33630 ↗ M c-ares CVE-2026-33630
CVE-2026-69184 ↗ M c-ares CVE-2026-69184
CVE-2026-69186 ↗ M c-ares CVE-2026-69186
CVE-2026-75803 ↗ L openssl CVE-2026-75803

1 further advisory matched this image and was assessed not to apply to it — see the VEX document for the reasoning and the evidence

CVE Affects Assessed
CVE-2026-27171 zlib not affected · vex

These are the findings of nodejs, which ships every tool in this project. kapsl reports and gates; it never edits an image to clear a finding.

Composition

default + bash, env
runtime none — self-contained
composes bash, env

Some tools are only useful composed: a pip-installed CLI needs python as its runtime, bash pulls in coreutils. kapsl resolves that for you — -e git,python:flake8 composes explicitly.

Image

image ghcr.io/kapsl-sh/nodejs:26.8.0
digest
platforms
size 134 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/kapsl-sh/nodejs:26.8.0
digest
platforms
size 134 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/kapsl-sh/nodejs:24.20.0
digest
platforms
size 122 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Image

image ghcr.io/kapsl-sh/nodejs:22.23.2
digest
platforms
size 126 MB unpacked · 1 layer
base scratch
signed cosign · verified
last scan

Sandbox boundary

node

capabilities

rw

Filled is granted to every invocation; the rest need --cap at the point of use.

seccomp tier

per tool

default

The syscall filter applied to this tool's entry point. Tools sharing an image do not share a tier.

dotfiles mapped in

read-only unless noted

  • ~/.node_repl_history · writable

env passed through

3 forwarded

NODE_DEBUGNODE_NO_WARNINGSNODE_OPTIONS

Nothing else crosses in. No AWS_*, no SSH_AUTH_SOCK unless you ask.

env set by kapsl

4 set

CPLUS_INCLUDE_PATHC_INCLUDE_PATHLIBRARY_PATHPKG_CONFIG_PATH

per-subcommand

no overrides

Every invocation gets the same boundary. Where a tool needs more for one subcommand only, kapsl scopes it there rather than granting it everywhere.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

Provenance

Every image ships a full SBOM and a signed build attestation. Nothing here is a claim you have to take on trust.

5 findings across this project at latest. Counted once per advisory across every image the project builds.