CVE-2026-48928: Medium severity OpenJS Node.js 22 vulnerability

Published Jun 26, 2026
·
Updated

A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups.

This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.

Affected Software

6 affected components
OpenJS Node.js 22=22
OpenJS Node.js 24=24
OpenJS Node.js 26=26
Nodejs Node.js=22.22.3
Nodejs Node.js=24.16.0
Nodejs Node.js=26.3.0

Event History

Jun 26, 2026
CVE Published
via MITRE·01:14 AM
Data Sourced
via MITRE·01:14 AM
DescriptionSeverityWeakness
Data Sourced
via Red Hat·02:02 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·02:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-48928?

The severity of CVE-2026-48928 is rated as medium with a CVSS score of 5.4.

2

How do I fix CVE-2026-48928?

CVE-2026-48928 can be fixed by applying the available patches provided in the Node.js security releases.

3

Which versions are affected by CVE-2026-48928?

CVE-2026-48928 affects all supported release lines of Node.js: version 22, version 24, and version 26.

4

What is the nature of CVE-2026-48928?

CVE-2026-48928 involves a hostname matching inconsistency that can lead to a trust-policy bypass in multi-context mTLS setups.

5

When was CVE-2026-48928 published?

CVE-2026-48928 was published on June 26, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203