CVE-2026-48934Patch(nodejs / node.js)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nodejs node.js systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node.js

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-06-26); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
node.js

3 versions affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-06-26: 1Mentions · 2026-07-31: 1Mentions · 2026-08-18: 1Patch / Workaround · 2026-07-31: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-06-26: 1Technical Details · 2026-07-31: 1Technical Details · 2026-08-18: 106-2607-3108-18
Signal classification2 categories
Patch
266.7%
General
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-261
General1
2026-07-311
Patch1
2026-08-181
Patch1
Full discourse3 posts
  • CyStack@CyStackSecurity
    Patch

    CVE-2026-58040: TLS session reuse in Node.js's HTTPS Agent can skip hostname verification. An incomplete fix for CVE-2026-48934. Reuse a session across different identity policies and the certificate check for the new host gets bypassed. Affects 22.x, 24.x, 26.x. Patched in v22.23.2, v24.18.1, v26.5.1. Found by a CyStack researcher. Details at https://cystack.net/disclosures

    Post summary

    The post discloses a TLS session reuse flaw in Node.js that bypasses hostname checks, specifies affected versions, and lists the vendor patches that mitigate the issue.

    0100058
    3.7K followersView on X
  • Luis Torres@4Ndr3w10000
    Patch

    Node security releases landed July 29 across 26.x, 24.x and 22.x. The HIGH one is CVE-2026-48934: HTTPS Agent TLS session reuse could skip hostname verification. If you pool https.Agent sockets across hosts, that is your bug. Patch today.

    Post summary

    The post announces a high‑severity CVE-2026-48934 affecting Node’s HTTPS Agent, notes the technical flaw of TLS session reuse skipping hostname verification, and urges users to apply the patch released on July 29.

    0001052
    43 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-48934 TLS Host Verification Bypass in Node.js 22, 24, and 26 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-48934

    Post summary

    A brief notice providing a CVE ID and a short description of a Node.js TLS host verification bypass, with no evidence of exploitation, mitigation, or PoC.

    00000107
    4.1K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js22.22.3--
Appnodejsnode.js24.16.0--
Appnodejsnode.js26.3.0--

Explore more