[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2026-48618":6},{"stargazers_count":4,"fetched_at":5},7,"2026-07-31T11:19:25.255Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":30,"aliases":31,"duplicate_of":9,"upstream":32,"downstream":33,"duplicates":82,"related":83,"reserved_at":9,"published_at":93,"modified_at":94,"state":95,"summary":96,"references_raw":105,"kevs":175,"epss":176,"epss_history":179,"metrics":210,"affected":218},"CVE-2026-48618","A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat.\r\n\r\nThis can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",null,[11,23],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-176","Improper Handling of Unicode Encoding","The product does not properly handle when an input contains Unicode encoding.","weakness","Draft","Variant",[19],{"id":20,"name":21,"techniques":22},"CAPEC-71","Using Unicode Encoding to Bypass Validation Logic",[],{"_key":24,"id":24,"name":25,"description":26,"type":15,"status":27,"abstraction":28,"likelihood_of_exploit":9,"capec":29},"CWE-289","Authentication Bypass by Alternate Name","The product performs authentication based on the name of a resource being accessed, or the name of the actor performing the access, but it does not properly check all possible names for that resource or actor.","Incomplete","Base",[],[],[],[],[34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64,66,68,70,72,74,76,78,80],{"_key":35},"OPENSUSE-SU-2026:11110-1",{"_key":37},"SUSE-SU-2026:2633-1",{"_key":39},"OPENSUSE-SU-2026:11121-1",{"_key":41},"SUSE-SU-2026:2647-1",{"_key":43},"DEBIAN-CVE-2026-48618",{"_key":45},"ALPINE-CVE-2026-48618",{"_key":47},"SUSE-SU-2026:22368-1",{"_key":49},"SUSE-SU-2026:2695-1",{"_key":51},"OPENSUSE-SU-2026:21058-1",{"_key":53},"OPENSUSE-SU-2026:21236-1",{"_key":55},"MGASA-2026-0257",{"_key":57},"SUSE-SU-2026:22565-1",{"_key":59},"RHSA-2026:28727",{"_key":61},"RHSA-2026:29012",{"_key":63},"RHSA-2026:30172",{"_key":65},"RHSA-2026:35841",{"_key":67},"RHSA-2026:35842",{"_key":69},"RHSA-2026:35891",{"_key":71},"RHSA-2026:35892",{"_key":73},"RHSA-2026:39246",{"_key":75},"RHSA-2026:39868",{"_key":77},"RHSA-2026:7378",{"_key":79},"RHSA-2026:9455",{"_key":81},"UBUNTU-CVE-2026-48618",[],[84,85,86,87,88,89,90,91,92],{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":57},"2026-06-26T01:14:36.868Z","2026-07-21T12:04:58.640Z","PUBLISHED",{"cisa_kev":97,"cisa_ransomware":97,"cisa_vendor":9,"epss_severity":98,"epss_score":99,"severity":100,"severity_score":101,"severity_version":102,"severity_source":103,"severity_vector":104,"severity_status":95},false,"low",0.00674,"high",7.7,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",[106,110,116,121,126,131,135,139,143,147,151,155,159,163,167,171],{"url":107,"sources":108,"tags":109},"https://nodejs.org/en/blog/vulnerability/june-2026-security-releases",[103],[],{"url":111,"sources":112,"tags":113},"https://access.redhat.com/security/cve/CVE-2026-48618",[103],[114,115],"VDB Entry","X Refsource REDHAT",{"url":117,"sources":118,"tags":119},"https://bugzilla.redhat.com/show_bug.cgi?id=2493337",[103],[120,115],"Issue Tracking",{"url":122,"sources":123,"tags":124},"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json",[103],[125],"X Sadp Csaf Vex",{"url":127,"sources":128,"tags":129},"https://access.redhat.com/errata/RHSA-2026:39246",[103],[130,115],"Vendor Advisory",{"url":132,"sources":133,"tags":134},"https://access.redhat.com/errata/RHSA-2026:35842",[103],[130,115],{"url":136,"sources":137,"tags":138},"https://access.redhat.com/errata/RHSA-2026:35841",[103],[130,115],{"url":140,"sources":141,"tags":142},"https://access.redhat.com/errata/RHSA-2026:39868",[103],[130,115],{"url":144,"sources":145,"tags":146},"https://access.redhat.com/errata/RHSA-2026:35892",[103],[130,115],{"url":148,"sources":149,"tags":150},"https://access.redhat.com/errata/RHSA-2026:35891",[103],[130,115],{"url":152,"sources":153,"tags":154},"https://access.redhat.com/errata/RHSA-2026:9455",[103],[130,115],{"url":156,"sources":157,"tags":158},"https://access.redhat.com/errata/RHSA-2026:28727",[103],[130,115],{"url":160,"sources":161,"tags":162},"https://access.redhat.com/errata/RHSA-2026:29012",[103],[130,115],{"url":164,"sources":165,"tags":166},"https://access.redhat.com/errata/RHSA-2026:7378",[103],[130,115],{"url":168,"sources":169,"tags":170},"https://access.redhat.com/errata/RHSA-2026:30172",[103],[130,115],{"url":172,"sources":173,"tags":174},"https://access.redhat.com/errata/RHSA-2026:41947",[103],[130,115],[],{"date":177,"score":99,"percentile":178},"2026-07-05",0.47695,[180,184,188,191,194,197,200,203,206,209],{"date":181,"score":182,"percentile":183},"2026-06-26",0.00609,0.4466,{"date":185,"score":186,"percentile":187},"2026-06-27",0.00612,0.44814,{"date":189,"score":186,"percentile":190},"2026-06-28",0.44811,{"date":192,"score":186,"percentile":193},"2026-06-29",0.44816,{"date":195,"score":186,"percentile":196},"2026-06-30",0.44787,{"date":198,"score":99,"percentile":199},"2026-07-01",0.47605,{"date":201,"score":99,"percentile":202},"2026-07-02",0.47643,{"date":204,"score":99,"percentile":205},"2026-07-03",0.4766,{"date":207,"score":99,"percentile":208},"2026-07-04",0.47687,{"date":177,"score":99,"percentile":178},[211],{"source":103,"cvss_v2_0":9,"cvss_v3_0":212,"cvss_v3_1":217,"cvss_v4_0":9},{"baseScore":101,"baseSeverity":213,"vectorString":214,"impactScore":215,"exploitabilityScore":216},"HIGH","CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N",6.7,7.9,{"baseScore":101,"baseSeverity":213,"vectorString":104,"impactScore":215,"exploitabilityScore":216},[219],{"ecosystem":9,"name":220,"vendor":221,"product":220,"cpe_part":222,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":223},"node","nodejs","a",[224,229,232],{"version":225,"is_range":226,"range_type":103,"version_start":227,"version_start_type":228,"version_end":227,"version_end_type":228,"fixed_in":9},">= 22.22.3, \u003C= 22.22.3",true,"22.22.3","including",{"version":230,"is_range":226,"range_type":103,"version_start":231,"version_start_type":228,"version_end":231,"version_end_type":228,"fixed_in":9},">= 24.16.0, \u003C= 24.16.0","24.16.0",{"version":233,"is_range":226,"range_type":103,"version_start":234,"version_start_type":228,"version_end":234,"version_end_type":228,"fixed_in":9},">= 26.3.0, \u003C= 26.3.0","26.3.0"]