logo

Critical Node.js Security Release Patches 12 Vulnerabilities Including Authentication Bypass

ID: a7019f9a-9a5a-5901-9d85-032cadedf492

STIX ID: report--a7019f9a-9a5a-5901-9d85-032cadedf492

Feed Name: Cyber Press

Threat Score
75/100

Date Published: 2026-06-19

Date Updated: 2026-06-19

Author: Lucas Martin

...
...

Node.js released critical security updates on June 18, 2026, addressing 12 CVEs across release lines 22.x, 24.x, and 26.x (patched to v22.23.0, v24.17.0, v26.3.1). Two high-severity flaws include a WebCrypto integer overflow that can trigger remote process aborts (CVE-2026-48933) and a TLS authentication bypass via hostname normalization (CVE-2026-48618); additional medium- and low-severity issues affect TLS hostname verification, HTTP/2 handling, proxy credential leakage, and permission-model races. Organizations should apply the updates immediately and audit TLS hostname validation, proxy settings, and HTTP/2 server implementations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.