Node.js [CVE-2026-48930] #75

Open
opened 2026-08-06 13:04:05 +00:00 by victor · 1 comment
Member

Installed: 24.16.0

A critical TLS hostname handling vulnerability in Node.js. Embedded null characters in hostnames trigger C-string truncation mismatches between lower-level resolver bindings and the upper-level TLS verifier, leading to silent authority rebinding and potential data exposure.

Affected and Fixed Versions

  • Node.js 22.x: Affected prior to v22.23.0
  • Node.js 24.x: Affected prior to v24.17.0
  • Node.js 26.x: Affected prior to v26.3.
Installed: 24.16.0 A critical TLS hostname handling vulnerability in Node.js. Embedded null characters in hostnames trigger C-string truncation mismatches between lower-level resolver bindings and the upper-level TLS verifier, leading to silent authority rebinding and potential data exposure. Affected and Fixed Versions - Node.js 22.x: Affected prior to v22.23.0 - Node.js 24.x: Affected prior to v24.17.0 - Node.js 26.x: Affected prior to v26.3.
victor added this to the Backlog milestone 2026-08-06 13:04:05 +00:00
victor self-assigned this 2026-08-06 13:04:48 +00:00
Author
Member

Update to version 24.18.0

Update to version [24.18.0](https://search.nixos.org/packages?channel=26.05&query=nodejs#show=nodejs_24)
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
MinBZK/DAWO-NixOS#75
No description provided.