Node.js Fixes 12 Vulnerabilities, Including 2 High-Severity Authentication Bypasses
ID: 90023962-a03b-53f4-bca8-a7a4356e61cf
STIX ID: report--90023962-a03b-53f4-bca8-a7a4356e61cf
Feed Name: cybersecurityNews.com
Node.js released security updates (June 18, 2026) addressing 12 CVEs affecting 22.x, 24.x, and 26.x, including two high-severity flaws: CVE-2026-48618 (Unicode dot separator handling allowing TLS wildcard authentication bypass) and CVE-2026-48933 (WebCrypto AES integer overflow causing remote process abort/DoS). Additional issues include TLS session-reuse host verification bypasses, SNI case-sensitive matching that can affect mTLS, HTTP/2 resource exhaustion, proxy credential leakage, permission-model bypasses, and several lower-severity bugs; maintainers also updated third-party dependencies (OpenSSL, llhttp, nghttp2, undici). Administrators are strongly advised to upgrade to Node.js v22.23.0, v24.17.0, or v26.3.1 and avoid end-of-life releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
