Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-48930: Node.js TLS Hostname Handling Can Cause Silent Authority Rebinding
CVE-2026-48930
BIT-node-2026-48930
Summary
A vulnerability in Node.js TLS (Transport Layer Security) hostname handling can allow attackers to secretly change the trusted server identity. This affects Node.js versions 22, 24, and 26. To protect your system, update to a patched version of Node.js as soon as possible.
What to do
- Update node-min to version 26.3.1.
- Update node to version 26.3.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| – | nodejs | node.js |
22.22.3 24.16.0 26.3.0 cpe:2.3:a:nodejs:node.js:22.22.3:*:*:*:-:*:*:* |
| Bitnami | – | node-min |
>= 26.3.0, < 26.3.1 Fix: upgrade to 26.3.1
|
| Bitnami | – | node |
>= 26.3.0, < 26.3.1 Fix: upgrade to 26.3.1
|
Original title
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings.
This vulnerability affects all su...
Original description
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings.
This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
nvd CVSS3.0
5.6
Vulnerability type
CWE-284
Improper Access Control
Published: 29 Jun 2026 · Updated: 23 Jul 2026 · First seen: 26 Jun 2026