PUBLISHED
Published: 26 Jun 2026, 01:14
Last modified:21 Jul 2026, 12:04

Vulnerability Summary

Overall Risk (default)
medium
31/100
CVSS Score
7.7 HIGH
v3.1 (cve.org)
EPSS Score
0.67% LOW
1% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Jun 2026, 01:14
Published
Vulnerability first disclosed
21 Jul 2026, 12:04
Last Modified
Vulnerability information updated

Description

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

CVSS Metrics

  • v3.1HIGHScore: 7.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
  • v3.0HIGHScore: 7.7CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.67% Percentile: 48%

Techniques & Countermeasures

  • CWE-176Improper Handling of Unicode Encoding

    The product does not properly handle when an input contains Unicode encoding.

  • CWE-289Authentication Bypass by Alternate Name

    The product performs authentication based on the name of a resource being accessed, or the name of the actor performing the access, but it does not properly check all possible names for that resource or actor.

Affected Systems

  • nodejsnode

    22.22.3 | 24.16.0 | 26.3.0

References (16)