Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-48934

Опубликовано: 26 июн. 2026
Источник: debian
EPSS Низкий

Описание

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nodejsfixed24.17.0+dfsg+~cs24.13.2-1package

Примечания

  • https://nodejs.org/en/blog/vulnerability/june-2026-security-releases#tls-host-identity-verification-bypass-via-session-reuse-with-different-servername-leads-to-unauthorized-connections-cve-2026-48934---medium

  • https://github.com/nodejs/node/commit/fd890ba01d508ac111bbba302981d7fdf734d2ce (v22.23.0)

  • When fixing this issue make sure to apply a complete fix to not open up CVE-2026-58040.

EPSS

Процентиль: 17%
0.00258
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
3 месяца назад

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 4.3
redhat
3 месяца назад

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 4.3
nvd
3 месяца назад

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS3: 4.3
github
3 месяца назад

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

rocky
около 2 месяцев назад

Important: nodejs:22 security, bug fix, and enhancement update

EPSS

Процентиль: 17%
0.00258
Низкий