PT-2026-52061 · Openjs Foundation+1 · Node.Js+1

·

CVE-2026-48930

·

Published

2026-06-19

·

Updated

2026-09-03

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Node.js versions 22.x and earlier Node.js versions 24.x and earlier Node.js versions 26.x and earlier
Description A flaw in TLS hostname handling allows embedded-nul hostnames to cause silent authority rebinding. This occurs due to c-string truncation in resolver bindings, where a null character in the hostname string terminates the string prematurely in the underlying C code, potentially leading the application to connect to an unintended destination.
Recommendations Update Node.js 22 to the latest patched version. Update Node.js 24 to the latest patched version. Update Node.js 26 to version 26.3.1-1.1 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:35841
ALSA-2026:35842
ALSA-2026:35891
ALSA-2026:35892
ALSA-2026:39868
ALSA-2026:41947
AZL-91221
BIT-NODE-2026-48930
BIT-NODE-MIN-2026-48930
CVE-2026-48930
ECHO-B334-8077-C795
OPENSUSE-SU-2026:11110-1
OPENSUSE-SU-2026:11121-1
OPENSUSE-SU-2026:21058-1
OPENSUSE-SU-2026:21236-1
RHSA-2026:33866
RHSA-2026:34478
RHSA-2026:35272
RHSA-2026:35841
RHSA-2026:35842
RHSA-2026:35891
RHSA-2026:35892
RHSA-2026:39868
RHSA-2026:7378
RHSA-2026:9455
SUSE-SU-2026:22368-1
SUSE-SU-2026:22565-1
SUSE-SU-2026:2633-1
SUSE-SU-2026:2647-1
SUSE-SU-2026:2695-1
SUSE-SU-2026:3929-1
SUSE-SU-2026:3930-1

Affected Products

Node.Js
Rocky Linux