CVE-2026-48934

Red Hat Security Advisory: nodejs:22 security, bug fix, and enhancement update

mediumEPSS 0.3%

Description

A flaw was found in Node.js. An attacker can exploit a vulnerability in the Transport Layer Security (TLS) host verification process to bypass certification validation. This bypass could allow an attacker to intercept or alter communications, potentially leading to information disclosure or integrity compromise.

Metrics

Severity
medium
no public PoC known
4.3
Source: nvd-v3
17.4 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-07-20 13:23 UTC

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-06-29 14:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • CWE: CWE-295

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • beaugunderson

    ip-address10.1.1

  • bitnami

    node-min22.22.3

  • bitnami

    node-min24.16.0

  • bitnami

    node-min26.3.0

  • IBM

    App Connect EnterpriseCD 13.4.0

  • IBM

    App Connect EnterpriseLTS 12.0.26

  • IBM

    App Connect EnterpriseLTS 13.4.0

  • nodejs

    undici6.17.0 – 6.27.0

  • nodejs

    undici7.0.0 – 7.28.0

  • nodejs

    undici8.0.0 – 8.5.0

References & sources

Linked CVEs

IDCVE-2026-48934