CVE-2026-48930Disclosure(nodejs / node.js)

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch nodejs node.js systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node.js

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-06-26); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
node.js

3 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-06-26: 1Mentions · 2026-06-27: 1Mentions · 2026-06-29: 1Mentions · 2026-07-24: 1PoC Mentioned / Linked · 2026-06-29: 1Patch / Workaround · 2026-06-27: 1Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-29: 106-2606-2706-2907-24
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-261
Disclosure1
2026-06-271
Disclosure1
2026-06-291
Disclosure1
2026-07-241
General1
Full discourse4 posts
  • SecAlerts@SecAlertsCo
    Disclosure

    🔗 Node.js TLS flaw: embedded null bytes in hostnames silently rebind authority via C-string truncation in resolver bindings. All supported versions affected. CVE-2026-48930 (CVSS 9.8) - patch now. https://secalerts.co/vulnerability/CVE-2026-48930?utm_campaign=x https://t.co/8cu054U3FM

    Post summary

    The tweet discloses a critical Node.js TLS flaw (CVE-2026-48930) with a CVSS of 9.8 and indicates that a patch is now available.

    01000129
    845 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    General

    掲載済みの脆弱性情報を更新しました。常に最新の脅威に対応できるよう、CISA KEVカタログとの突合結果を反映し、レビューノートを追加しています。 https://cve.autoarticles.net/cve/CVE-2026-48930

    Post summary

    The post updates CVE-2026-48930 by noting cross‑matching with the CISA KEV catalog and adding review notes, but it does not provide PoC, exploit, patch, or technical details.

    0000048
    561 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 CRITICAL: CVE-2026-48930 — Node.js TLS Hostname Truncation CVSS 9.8 (NVD). NUL byte injection causes hostname truncation → authority rebinding → TLS impersonation. Affects Node.js 22.x, 24.x, 26.x. 🔗 https://threataft.com/articles/cve-2026-48930-nodejs-tls-hostname-truncation-authority-rebinding #CyberSecurity #ThreatIntel #infosec #nodejs

    Post summary

    A critical Node.js TLS hostname truncation vulnerability (CVE‑2026‑48930) is disclosed, detailing NUL byte injection leading to TLS impersonation and affecting Node.js 22.x, 24.x, and 26.x.

    0000077
    31 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-48930 Embedded-Nul Hostname TLS Vulnerability in Node.js 22, 24, and 26 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-48930

    Post summary

    The text announces a new Node.js TLS vulnerability (CVE‑2026‑48930) affecting versions 22, 24, and 26, providing basic technical details but no PoC, exploit code, exploitation evidence, or patch information.

    00000113
    4.1K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js22.22.3--
Appnodejsnode.js24.16.0--
Appnodejsnode.js26.3.0--

Explore more