6.5

CVE-2026-48618

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat.

This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.

This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nodejs ≫ Node.Js Version 22.22.3 SwEdition -
Nodejs ≫ Node.Js Version 24.16.0 SwEdition -
Nodejs ≫ Node.Js Version 26.3.0 SwEdition -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.23% 0.869
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 7.7 3.1 4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
HackerOne 7.7 3.1 4
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
CWE-176 Improper Handling of Unicode Encoding

The product does not properly handle when an input contains Unicode encoding.

CWE-289 Authentication Bypass by Alternate Name

The product performs authentication based on the name of a resource being accessed, or the name of the actor performing the access, but it does not properly check all possible names for that resource or actor.

https://nodejs.org/en/blog/vulnerability/june-2026-security-releases
Patch
Vendor Advisory
https://access.redhat.com/errata/RHSA-2026:35841
https://access.redhat.com/errata/RHSA-2026:35842
https://access.redhat.com/errata/RHSA-2026:35891
https://access.redhat.com/errata/RHSA-2026:35892
https://access.redhat.com/errata/RHSA-2026:7378
https://access.redhat.com/errata/RHSA-2026:28727
https://access.redhat.com/errata/RHSA-2026:29012
https://access.redhat.com/errata/RHSA-2026:30172
https://access.redhat.com/errata/RHSA-2026:9455
https://access.redhat.com/errata/RHSA-2026:39246
https://access.redhat.com/security/cve/CVE-2026-48618
https://bugzilla.redhat.com/show_bug.cgi?id=2493337
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json
https://access.redhat.com/errata/RHSA-2026:39868
https://access.redhat.com/errata/RHSA-2026:41947
https://access.redhat.com/errata/RHSA-2026:52399