CVE-2026-48928: Medium severity OpenJS Node.js 22 vulnerability
Published Jun 26, 2026
·Updated
A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups.
This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
Affected Software
6 affected components
OpenJS Node.js 22=22
OpenJS Node.js 24=24
OpenJS Node.js 26=26
Nodejs Node.js=22.22.3
Nodejs Node.js=24.16.0
Nodejs Node.js=26.3.0
Remediation
Event History
Jun 26, 2026
CVE Published
via MITRE·01:14 AM
Data Sourced
via MITRE·01:14 AM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·02:02 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·02:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48928?
The severity of CVE-2026-48928 is rated as medium with a CVSS score of 5.4.
2
How do I fix CVE-2026-48928?
CVE-2026-48928 can be fixed by applying the available patches provided in the Node.js security releases.
3
Which versions are affected by CVE-2026-48928?
CVE-2026-48928 affects all supported release lines of Node.js: version 22, version 24, and version 26.
4
What is the nature of CVE-2026-48928?
CVE-2026-48928 involves a hostname matching inconsistency that can lead to a trust-policy bypass in multi-context mTLS setups.
5
When was CVE-2026-48928 published?
CVE-2026-48928 was published on June 26, 2026.