CVE-2026-48934: Medium severity Node.js 22 vulnerability
Published Jun 26, 2026
·Updated
A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation.
This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
Affected Software
6 affected components
Node.js 22=22
Node.js 24=24
Node.js 26=26
Nodejs Node.js=22.22.3
Nodejs Node.js=24.16.0
Nodejs Node.js=26.3.0
Remediation
Event History
Jun 26, 2026
CVE Published
via MITRE·01:14 AM
Data Sourced
via MITRE·01:14 AM
DescriptionSeverity
Data Sourced
via Red Hat·02:02 AM
DescriptionSeverityAffected Software
Data Sourced
via NVD·02:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48934?
CVE-2026-48934 has a medium severity rating of 4.3.
2
How do I fix CVE-2026-48934?
You can fix CVE-2026-48934 by applying the available patch for Node.js.
3
Which versions of Node.js are affected by CVE-2026-48934?
CVE-2026-48934 affects Node.js versions 22, 24, and 26.
4
What risk does CVE-2026-48934 pose?
CVE-2026-48934 poses a risk of bypassing TLS certification validation.
5
What type of vulnerability is CVE-2026-48934?
CVE-2026-48934 is a flaw in Node.js TLS host verification.