Описание
A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups.
This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
A flaw was found in Node.js. An inconsistency in how Node.js matches hostnames can be exploited by a remote attacker in multi-context mTLS (mutual Transport Layer Security) setups. This vulnerability allows for a trust-policy bypass, potentially leading to unauthorized access to sensitive information or integrity compromise within the affected system.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 8 | nodejs | Fix deferred | ||
| Red Hat Enterprise Linux 10 | nodejs24 | Fixed | RHSA-2026:35841 | 06.07.2026 |
| Red Hat Enterprise Linux 10 | nodejs22 | Fixed | RHSA-2026:35842 | 06.07.2026 |
| Red Hat Enterprise Linux 8 | nodejs | Fixed | RHSA-2026:39868 | 15.07.2026 |
| Red Hat Enterprise Linux 8 | nodejs | Fixed | RHSA-2026:41947 | 20.07.2026 |
| Red Hat Enterprise Linux 9 | nodejs | Fixed | RHSA-2026:35891 | 06.07.2026 |
| Red Hat Enterprise Linux 9 | nodejs | Fixed | RHSA-2026:35892 | 06.07.2026 |
| Red Hat Hardened Images | nodejs26-main-26.4.0-1.3.hum1 | Fixed | RHSA-2026:33866 | 30.06.2026 |
| Red Hat Hardened Images | nodejs24-main-24.18.0-0.2.hum1 | Fixed | RHSA-2026:34478 | 01.07.2026 |
| Red Hat Hardened Images | nodejs22-main-22.23.1-2.hum1 | Fixed | RHSA-2026:35272 | 03.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.2 Medium
CVSS3
Связанные уязвимости
A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
A inconsistency in Node.js hostname matching can cause a trust-policy ...
A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
EPSS
4.2 Medium
CVSS3