
🔗 Node.js TLS flaw: embedded null bytes in hostnames silently rebind authority via C-string truncation in resolver bindings. All supported versions affected. CVE-2026-48930 (CVSS 9.8) - patch now. https://secalerts.co/vulnerability/CVE-2026-48930?utm_campaign=x https://t.co/8cu054U3FM
Post summary
The tweet discloses a critical Node.js TLS flaw (CVE-2026-48930) with a CVSS of 9.8 and indicates that a patch is now available.



