Improper Null Termination in Node.js - CVE-2026-48930
Published: June 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass hostname-based authority checks.
The vulnerability exists due to c-string truncation in resolver bindings in TLS hostname handling when processing hostnames containing an embedded nul character. A remote attacker can present a crafted hostname to bypass hostname-based authority checks.
Affected software
Anolis OS
nodejs-npm
v8-12.4-devel
nodejs
nodejs-devel
nodejs-full-i18n
nodejs-libs
nodejs-docs
How to mitigate CVE-2026-48930
nodejs-npm - update to 10.9.8-1.22.23.0.1
v8-12.4-devel - update to 12.4.254.21-1.22.23.0.1
nodejs - update to 22.23.0-1
nodejs-devel - update to 22.23.0-1
nodejs-full-i18n - update to 22.23.0-1
nodejs-libs - update to 22.23.0-1
nodejs-docs - update to 22.23.0-1