CVE-2026-48930

NONEEPSS 0.28%

Last modified

This CVE is reserved or awaiting analysis. Details will appear once published by NVD.

Description

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

Metrics

CVSS 3.0
/10
EPSS Probability
0.28%

19.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

References

Timeline

Published
Last Modified
Status
Awaiting Analysis

Are you affected by CVE-2026-48930?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST