Openjs Foundation · Node.Js · CVE-2026-48618
**Name of the Vulnerable Software and Affected Versions**
Node.js versions 22.x through 26.3.0
**Description**
A flaw in TLS hostname handling occurs when Node.js processes unicode dot separators, leading to a mismatch between resolver and verifier hostname normalization. This discrepancy can result in a TLS wildcard-depth authentication bypass, potentially compromising confidentiality or bypassing intended security boundaries under affected configurations.
**Recommendations**
Update Node.js to version 26.3.1 or later.