Improper Null Termination in Node.js - CVE-2026-48930
Published: June 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass hostname-based authority checks.
The vulnerability exists due to c-string truncation in resolver bindings in TLS hostname handling when processing hostnames containing an embedded nul character. A remote attacker can present a crafted hostname to bypass hostname-based authority checks.
Affected software
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server 15 SP5
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
openSUSE Leap
Anolis OS
Fedora
nodejs-npm
v8-12.4-devel
nodejs18-docs
nodejs18-debugsource
nodejs18-debuginfo
nodejs18
npm18
nodejs18-devel
corepack18
nodejs
nodejs-docs
nodejs-libs
nodejs-full-i18n
nodejs-devel
nodejs22
nodejs24
How to mitigate CVE-2026-48930
nodejs-npm - update to 10.9.8-1.22.23.0.1
v8-12.4-devel - update to 12.4.254.21-1.22.23.0.1
nodejs18-docs - addressed in versions 18.20.8-8.44.1, 18.20.8-150400.9.39.1
nodejs18-debugsource - addressed in versions 18.20.8-8.44.1, 18.20.8-150400.9.39.1
nodejs18-debuginfo - addressed in versions 18.20.8-8.44.1, 18.20.8-150400.9.39.1
nodejs18 - addressed in versions 18.20.8-8.44.1, 18.20.8-150400.9.39.1
npm18 - addressed in versions 18.20.8-8.44.1, 18.20.8-150400.9.39.1
nodejs18-devel - addressed in versions 18.20.8-8.44.1, 18.20.8-150400.9.39.1
corepack18 - update to 18.20.8-150400.9.39.1
nodejs - update to 22.23.0-1
nodejs-docs - update to 22.23.0-1
nodejs-libs - update to 22.23.0-1
nodejs-full-i18n - update to 22.23.0-1
nodejs-devel - update to 22.23.0-1
nodejs22 - update to 22.23.1-2.fc44
nodejs24 - update to 24.18.0-1.fc44
External References
Related Security Bulletins
- Multiple vulnerabilities in Node.js
- Anolis OS update for nodejs
- Fedora 44 update for nodejs24
- Fedora 44 update for nodejs22
- Red Hat Enterprise Linux 9 update for the nodejs:24 module
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Red Hat Enterprise Linux 8 update for the nodejs:24 module
- Red Hat Enterprise Linux 8 update for the nodejs:22 module
- SUSE update for nodejs18
- SUSE update for nodejs18