CVE-2026-48934
Red Hat Security Advisory: nodejs:22 security, bug fix, and enhancement update
Description
A flaw was found in Node.js. An attacker can exploit a vulnerability in the Transport Layer Security (TLS) host verification process to bypass certification validation. This bypass could allow an attacker to intercept or alter communications, potentially leading to information disclosure or integrity compromise.
Metrics
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-06-29 14:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE: CWE-295
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
beaugunderson
ip-address10.1.1
bitnami
node-min22.22.3
bitnami
node-min24.16.0
bitnami
node-min26.3.0
IBM
App Connect EnterpriseCD 13.4.0
IBM
App Connect EnterpriseLTS 12.0.26
IBM
App Connect EnterpriseLTS 13.4.0
nodejs
undici6.17.0 – 6.27.0
nodejs
undici7.0.0 – 7.28.0
nodejs
undici8.0.0 – 8.5.0
References & sources
- https://nodejs.org/en/blog/vulnerability/june-2026-security-releasesweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-48619web
- https://nvd.nist.gov/vuln/detail/CVE-2026-48615web
- https://github.com/nodejs/undici/security/advisories/GHSA-vxpw-j846-p89qweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-12151advisory
- https://cna.openjsf.org/security-advisories.htmlweb
- https://github.com/nodejs/undicipackage
- https://access.redhat.com/security/cve/CVE-2026-12151vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2489980issue-trackingx_refsource_REDHAT
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-12151.jsonx_sadp-csaf-vex
- https://access.redhat.com/errata/RHSA-2026:48151vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:39246vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:35842vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:35841vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:41947vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:39868vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:35892vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:35891vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:34342vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:36754vendor-advisoryx_refsource_REDHAT
Linked CVEs
- CVE-2026-9678
A flaw was found in Undici.
mediumCVSSv3 5.9 - CVE-2026-6733
A flaw was found in undici.
lowCVSSv3 3.7 - CVE-2026-48935
A flaw was found in Node.js.
lowCVSSv3 3.3 - CVE-2026-48933
A flaw was found in the Node.js WebCrypto implementation.
highCVSSv3 7.5 - CVE-2026-48930
A flaw was found in Node.js.
mediumCVSSv3 5.6 - CVE-2026-48928
A flaw was found in Node.js.
mediumCVSSv3 4.2 - CVE-2026-48619
A flaw was found in Node.js.
mediumCVSSv3 5.3 - CVE-2026-48618
A flaw was found in Node.js.
highCVSSv3 7.7 - CVE-2026-48615
A flaw was found in Node.js.
mediumCVSSv3 5.9 - CVE-2026-42338
A flaw was found in ip-address, a JavaScript library for parsing and manipulating IPv4 and IPv6 addresses.
highCVSSv3 8.1 - CVE-2026-12151
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-11525
A flaw was found in undici.
lowCVSSv3 3.7