logo

Node.js Fixes 12 Vulnerabilities, Including 2 High-Severity Authentication Bypasses

ID: 90023962-a03b-53f4-bca8-a7a4356e61cf

STIX ID: report--90023962-a03b-53f4-bca8-a7a4356e61cf

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Abinaya

...
...

Node.js released security updates (June 18, 2026) addressing 12 CVEs affecting 22.x, 24.x, and 26.x, including two high-severity flaws: CVE-2026-48618 (Unicode dot separator handling allowing TLS wildcard authentication bypass) and CVE-2026-48933 (WebCrypto AES integer overflow causing remote process abort/DoS). Additional issues include TLS session-reuse host verification bypasses, SNI case-sensitive matching that can affect mTLS, HTTP/2 resource exhaustion, proxy credential leakage, permission-model bypasses, and several lower-severity bugs; maintainers also updated third-party dependencies (OpenSSL, llhttp, nghttp2, undici). Administrators are strongly advised to upgrade to Node.js v22.23.0, v24.17.0, or v26.3.1 and avoid end-of-life releases.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.