PT-2026-50893 · Openjs Foundation+1 · Node.Js+1

·

CVE-2026-48618

·

Published

2026-06-19

·

Updated

2026-09-03

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Node.js versions 22.x through 26.3.0
Description A flaw in TLS hostname handling occurs when Node.js processes unicode dot separators, leading to a mismatch between resolver and verifier hostname normalization. This discrepancy can result in a TLS wildcard-depth authentication bypass, potentially compromising confidentiality or bypassing intended security boundaries under affected configurations.
Recommendations Update Node.js to version 26.3.1 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:35841
ALSA-2026:35842
ALSA-2026:35891
ALSA-2026:35892
ALSA-2026:39868
ALSA-2026:41947
AZL-91224
BIT-NODE-2026-48618
BIT-NODE-MIN-2026-48618
CVE-2026-48618
ECHO-321F-39D2-90A5
OPENSUSE-SU-2026:11110-1
OPENSUSE-SU-2026:11121-1
OPENSUSE-SU-2026:21058-1
OPENSUSE-SU-2026:21236-1
RHSA-2026:35841
RHSA-2026:35842
RHSA-2026:35891
RHSA-2026:35892
RHSA-2026:39868
RHSA-2026:52399
RHSA-2026:7378
RHSA-2026:9455
SUSE-SU-2026:22368-1
SUSE-SU-2026:22565-1
SUSE-SU-2026:2633-1
SUSE-SU-2026:2647-1
SUSE-SU-2026:2695-1
SUSE-SU-2026:3929-1
SUSE-SU-2026:3930-1

Affected Products

Node.Js
Rocky Linux