CVE-2026-48928
EUVD-2026-3961326.06.2026, 02:16
A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| nodejs | node.js | 22.22.3 |
| nodejs | node.js | 24.16.0 |
| nodejs | node.js | 26.3.0 |
𝑥
= Vulnerable software versions
Debian Releases
openSUSE / SLES Releases
openSUSE Product | |||||
|---|---|---|---|---|---|
| nodejs22 |
| ||||
| nodejs22-devel |
| ||||
| nodejs22-docs |
| ||||
| nodejs24 |
| ||||
| nodejs24-devel |
| ||||
| nodejs24-docs |
| ||||
| npm22 |
| ||||
| npm24 |
|
Common Weakness Enumeration
Vulnerability Media Exposure