CVE-2026-48930: Critical severity nodejs/Node.js 22 vulnerability
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings.
This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nodejsto a version that resolves this vulnerability.Fixed in Node.js 26 - Upgrade
Upgrade
nodejsto a version that resolves this vulnerability.Fixed in Node.js 24 - Upgrade
Upgrade
nodejsto a version that resolves this vulnerability.Fixed in Node.js 22
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48930?
The severity of CVE-2026-48930 is critical with a score of 9.8.
How do I fix CVE-2026-48930?
You can fix CVE-2026-48930 by applying the available patches for Node.js versions 22, 24, and 26.
What systems are affected by CVE-2026-48930?
CVE-2026-48930 affects all supported release lines of Node.js: 22, 24, and 26.
What is the description of CVE-2026-48930?
CVE-2026-48930 is a flaw in Node.js TLS hostname handling that can lead to silent authority rebinding due to c-string truncation.
When was CVE-2026-48930 published?
CVE-2026-48930 was published on June 26, 2026.