PT-2026-52060 · Openjs Foundation+1 · Node.Js+1

·

CVE-2026-48928

·

Published

2026-06-19

·

Updated

2026-09-03

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Node.js versions 22.x and earlier Node.js versions 24.x and earlier Node.js versions 26.0.0 through 26.3.0
Description An inconsistency in hostname matching can lead to a trust-policy bypass within multi-context mTLS (mutual Transport Layer Security) setups. mTLS is a process where both the client and server authenticate each other using digital certificates.
Recommendations Update Node.js 22 to the latest patched version. Update Node.js 24 to the latest patched version. Update Node.js 26 to version 26.3.1-1.1 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:35841
ALSA-2026:35842
ALSA-2026:35891
ALSA-2026:35892
ALSA-2026:39868
ALSA-2026:41947
AZL-91209
BIT-NODE-2026-48928
BIT-NODE-MIN-2026-48928
CVE-2026-48928
ECHO-5859-A1F1-B62C
OPENSUSE-SU-2026:11110-1
OPENSUSE-SU-2026:11121-1
OPENSUSE-SU-2026:21058-1
OPENSUSE-SU-2026:21236-1
RHSA-2026:33866
RHSA-2026:34478
RHSA-2026:35272
RHSA-2026:35841
RHSA-2026:35842
RHSA-2026:35891
RHSA-2026:35892
RHSA-2026:39868
RHSA-2026:7378
RHSA-2026:9455
SUSE-SU-2026:22368-1
SUSE-SU-2026:22565-1
SUSE-SU-2026:2633-1
SUSE-SU-2026:2647-1
SUSE-SU-2026:2695-1
SUSE-SU-2026:3929-1
SUSE-SU-2026:3930-1

Affected Products

Node.Js
Rocky Linux