CVE-2026-48618
Summary
| CVE | CVE-2026-48618 |
|---|---|
| State | PUBLISHED |
| Assigner | hackerone |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-26 02:16:52 UTC |
| Updated | 2026-07-21 12:18:50 UTC |
| Description | A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. |
Risk And Classification
Primary CVSS: v3.1 6.5 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.024860000 probability, percentile 0.828560000 (date 2026-07-21)
Problem Types: CWE-176 | CWE-289 | CWE-176 CWE-176 Improper Handling of Unicode Encoding | CWE-289 Authentication Bypass by Alternate Name
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | ADP | CVSS | 7.7 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
| 3.1 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | Secondary | 7.7 | HIGH | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
| 3.0 | [email protected] | Secondary | 7.7 | HIGH | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
| 3.0 | CNA | DECLARED | 7.7 | HIGH | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N |
CVSS v3.1 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v3.0 Breakdown
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Nodejs | Node | affected 22.22.3 22.22.3 semver | Not specified |
| CNA | Nodejs | Node | affected 24.16.0 24.16.0 semver | Not specified |
| CNA | Nodejs | Node | affected 26.3.0 26.3.0 semver | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10 | unaffected 1:24.18.0-1.el10_2 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10 | unaffected 1:22.23.1-2.el10_2 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 10.0 Extended Update Support | unaffected 1:22.23.1-2.el10_0 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | unaffected 8100020260630152626.6d880403 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 8 | unaffected 8100020260703140402.6d880403 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | unaffected 9080020260626074955.rhel9 * rpm | Not specified |
| ADP | Red Hat | Red Hat Enterprise Linux 9 | unaffected 9080020260626075442.rhel9 * rpm | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | unaffected 22.23.1-1.hum1 * rpm | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | unaffected 24.18.0-0.1.hum1 * rpm | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | unaffected 26.4.0-1.2.hum1 * rpm | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | unaffected 25.9.0-1.1.hum1 * rpm | Not specified |
| ADP | Red Hat | Red Hat Hardened Images | unaffected 20.20.2-1.hum1 * rpm | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| access.redhat.com/errata/RHSA-2026:7378 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/security/cve/CVE-2026-48618 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:35891 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:35842 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:41947 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| nodejs.org/en/blog/vulnerability/june-2026-security-releases | [email protected] | nodejs.org | Patch, Vendor Advisory |
| access.redhat.com/errata/RHSA-2026:28727 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:35892 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:35841 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | security.access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:39246 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| bugzilla.redhat.com/show_bug.cgi | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | bugzilla.redhat.com | |
| access.redhat.com/errata/RHSA-2026:39868 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:9455 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:29012 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| access.redhat.com/errata/RHSA-2026:30172 | 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | access.redhat.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Additional Advisory Data
| Source | Time | Event |
|---|---|---|
| ADP | 2026-06-26T02:02:10.741Z | Reported to Red Hat. |
| ADP | 2026-06-26T01:14:36.868Z | Made public. |
Solutions
ADP: RHSA-2026:39246: Red Hat Enterprise Linux AppStream EUS (v. 10.0)
ADP: RHSA-2026:35842: Red Hat Enterprise Linux AppStream (v. 10)
ADP: RHSA-2026:35841: Red Hat Enterprise Linux AppStream (v. 10)
ADP: RHSA-2026:41947: Red Hat Enterprise Linux AppStream (v. 8)
ADP: RHSA-2026:39868: Red Hat Enterprise Linux AppStream (v. 8)
ADP: RHSA-2026:35892: Red Hat Enterprise Linux AppStream (v. 9)
ADP: RHSA-2026:35891: Red Hat Enterprise Linux AppStream (v. 9)
ADP: RHSA-2026:9455: Red Hat Hardened Images
ADP: RHSA-2026:28727: Red Hat Hardened Images
ADP: RHSA-2026:29012: Red Hat Hardened Images
ADP: RHSA-2026:7378: Red Hat Hardened Images
ADP: RHSA-2026:30172: Red Hat Hardened Images
Workarounds
ADP: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.