Overview
What is CVE-2026-48934?
A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Vulnerability intelligence
CVE-2026-48934 and is rated Medium severity with a CVSS score of 4.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.