CVE-2026-48618

EUVD-2026-39610
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat.

This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.

This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 44%
Affected Products (NVD)
VendorProductVersion
nodejsnode.js
22.22.3
nodejsnode.js
24.16.0
nodejsnode.js
26.3.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
nodejs
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
24.17.0+dfsg+~cs24.13.2-1
fixed
sid
24.17.0+dfsg+~cs24.13.2-1
fixed
trixie
vulnerable
trixie (security)
vulnerable
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
nodejs22
suse enterprise server 15 SP6
22.23.0-150600.13.18.1
fixed
nodejs22-devel
suse enterprise server 15 SP6
22.23.0-150600.13.18.1
fixed
nodejs22-docs
suse enterprise server 15 SP6
22.23.0-150600.13.18.1
fixed
nodejs24
suse enterprise sap 15 SP7
24.17.0-150700.15.11.1
fixed
suse enterprise server 15 SP7
24.17.0-150700.15.11.1
fixed
nodejs24-devel
suse enterprise sap 15 SP7
24.17.0-150700.15.11.1
fixed
suse enterprise server 15 SP7
24.17.0-150700.15.11.1
fixed
nodejs24-docs
suse enterprise sap 15 SP7
24.17.0-150700.15.11.1
fixed
suse enterprise server 15 SP7
24.17.0-150700.15.11.1
fixed
npm22
suse enterprise server 15 SP6
22.23.0-150600.13.18.1
fixed
npm24
suse enterprise sap 15 SP7
24.17.0-150700.15.11.1
fixed
suse enterprise server 15 SP7
24.17.0-150700.15.11.1
fixed