Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-48930: Node.js TLS Hostname Handling Can Cause Silent Authority Rebinding

CVE-2026-48930 BIT-node-2026-48930
Summary

A vulnerability in Node.js TLS (Transport Layer Security) hostname handling can allow attackers to secretly change the trusted server identity. This affects Node.js versions 22, 24, and 26. To protect your system, update to a patched version of Node.js as soon as possible.

What to do
  • Update node-min to version 26.3.1.
  • Update node to version 26.3.1.
Affected software
Ecosystem VendorProductAffected versions
nodejs node.js 22.22.3
24.16.0
26.3.0
cpe:2.3:a:nodejs:node.js:22.22.3:*:*:*:-:*:*:*
Bitnami node-min >= 26.3.0, < 26.3.1
Fix: upgrade to 26.3.1
Bitnami node >= 26.3.0, < 26.3.1
Fix: upgrade to 26.3.1
Original title
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all su...
Original description
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings.

This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
nvd CVSS3.0 5.6
Vulnerability type
CWE-284 Improper Access Control
Published: 29 Jun 2026 · Updated: 23 Jul 2026 · First seen: 26 Jun 2026