PT-2026-50893 · Openjs Foundation+1 · Node.Js+1
CVSS v3.1
7.7
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Node.js versions 22.x through 26.3.0
Description
A flaw in TLS hostname handling occurs when Node.js processes unicode dot separators, leading to a mismatch between resolver and verifier hostname normalization. This discrepancy can result in a TLS wildcard-depth authentication bypass, potentially compromising confidentiality or bypassing intended security boundaries under affected configurations.
Recommendations
Update Node.js to version 26.3.1 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Node.Js
Rocky Linux