Improper Null Termination in Node.js - CVE-2026-48930
Published: June 22, 2026
Node.js
Detailed vulnerability description
The vulnerability allows a remote attacker to bypass hostname-based authority checks.
The vulnerability exists due to c-string truncation in resolver bindings in TLS hostname handling when processing hostnames containing an embedded nul character. A remote attacker can present a crafted hostname to bypass hostname-based authority checks.