CVE-2026-48618: CWE-176 Improper Handling of Unicode Encoding in nodejs node
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
AI Analysis
Technical Summary
This vulnerability arises from a mismatch in how Node.js handles TLS hostname verification and Unicode dot separators, causing a wildcard-depth authentication bypass. The flaw affects all supported Node.js release lines 22, 24, and 26 as shipped in Red Hat products. The issue is classified under CWE-176 (Improper Handling of Unicode Encoding) and CWE-289 (Authentication Bypass by Alternate Name). Red Hat's advisory confirms the vulnerability and provides updated Node.js packages that fix the issue. The CVSS v3 base score is 7.7, indicating high severity, with network attack vector, low complexity, low privileges required, no user interaction, and a changed scope with high confidentiality impact but no integrity or availability impact.
Potential Impact
The vulnerability allows an attacker to bypass TLS hostname verification due to improper Unicode dot separator handling, potentially leading to unauthorized access and compromise of confidentiality in applications using Node.js TLS connections. There is no reported impact on integrity or availability. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Red Hat has released updated Node.js packages (e.g., nodejs22-22.23.1) that address this vulnerability. Applying these official security updates is the recommended remediation. Currently, no alternative mitigations meet Red Hat's criteria for ease of use and stability. Users should upgrade affected Node.js versions to the patched releases provided by Red Hat. Check the vendor advisory for detailed update instructions.
CVE-2026-48618: CWE-176 Improper Handling of Unicode Encoding in nodejs node
Description
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
CVSS v3.0
Score 7.7high
Affected software
nodejs
node
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability arises from a mismatch in how Node.js handles TLS hostname verification and Unicode dot separators, causing a wildcard-depth authentication bypass. The flaw affects all supported Node.js release lines 22, 24, and 26 as shipped in Red Hat products. The issue is classified under CWE-176 (Improper Handling of Unicode Encoding) and CWE-289 (Authentication Bypass by Alternate Name). Red Hat's advisory confirms the vulnerability and provides updated Node.js packages that fix the issue. The CVSS v3 base score is 7.7, indicating high severity, with network attack vector, low complexity, low privileges required, no user interaction, and a changed scope with high confidentiality impact but no integrity or availability impact.
Potential Impact
The vulnerability allows an attacker to bypass TLS hostname verification due to improper Unicode dot separator handling, potentially leading to unauthorized access and compromise of confidentiality in applications using Node.js TLS connections. There is no reported impact on integrity or availability. No known exploits are reported in the wild at this time.
Mitigation Recommendations
Red Hat has released updated Node.js packages (e.g., nodejs22-22.23.1) that address this vulnerability. Applying these official security updates is the recommended remediation. Currently, no alternative mitigations meet Red Hat's criteria for ease of use and stability. Users should upgrade affected Node.js versions to the patched releases provided by Red Hat. Check the vendor advisory for detailed update instructions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- hackerone
- Date Reserved
- 2026-05-22T15:00:09.276Z
- Cvss Version
- 3.0
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-48618","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:39246","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:35842","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:35841","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:35892","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:35891","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:9455","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:28727","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:29012","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:7378","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:30172","vendor":"Red Hat"}]
Threat ID: 6a3dd65f4853345fc1fa2e22
Added to database: 06/26/2026, 01:31:11 UTC
Last enriched: 08/10/2026, 13:01:07 UTC
Last updated: 09/24/2026, 02:00:37 UTC
Views: 232
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.