CVE-2026-48931: Low severity Node.js Node.js vulnerability
Published Jun 22, 2026
·Updated
A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
Affected Software
4 affected components
Node.js Node.js>=22.0.0<=22.x, >=24.0.0<=24.x, >=26.0.0<=26.x
Nodejs Node.js=22.22.3
Nodejs Node.js=24.16.0
Nodejs Node.js=26.3.0
Event History
Jun 22, 2026
CVE Published
via MITRE·06:59 PM
Data Sourced
via MITRE·06:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48931?
CVE-2026-48931 has a low severity rating of 3.7.
2
How do I fix CVE-2026-48931?
To mitigate CVE-2026-48931, ensure that you are using an updated version of Node.js that addresses this vulnerability.
3
What types of systems are affected by CVE-2026-48931?
CVE-2026-48931 affects all supported release lines of Node.js: 22, 24, and 26.
4
What is the risk associated with CVE-2026-48931?
The risk associated with CVE-2026-48931 is considered low, but it can lead to validation issues with responses from the HTTP Agent.
5
When was CVE-2026-48931 published?
CVE-2026-48931 was published on June 22, 2026.