Critical Node.js Security Release Patches 12 Vulnerabilities Including Authentication Bypass
ID: a7019f9a-9a5a-5901-9d85-032cadedf492
STIX ID: report--a7019f9a-9a5a-5901-9d85-032cadedf492
Feed Name: Cyber Press
Node.js released critical security updates on June 18, 2026, addressing 12 CVEs across release lines 22.x, 24.x, and 26.x (patched to v22.23.0, v24.17.0, v26.3.1). Two high-severity flaws include a WebCrypto integer overflow that can trigger remote process aborts (CVE-2026-48933) and a TLS authentication bypass via hostname normalization (CVE-2026-48618); additional medium- and low-severity issues affect TLS hostname verification, HTTP/2 handling, proxy credential leakage, and permission-model races. Organizations should apply the updates immediately and audit TLS hostname validation, proxy settings, and HTTP/2 server implementations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
