DEBIAN-CVE-2026-48618
Advisory lineage Upstream: 1 Downstream: 0
Upstream
Published: 26 Jun 2026, 02:16
Last modified:27 Jun 2026, 10:00
Vulnerability Summary
Overall Risk (default)
medium
26/100 CVSS Score
6.5 MEDIUM
3.1 (osv_debian)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
26 Jun 2026, 02:16
Published
Vulnerability first disclosed
27 Jun 2026, 10:00
Last Modified
Vulnerability information updated
Description
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
CVSS Metrics
- v3.1•MEDIUM•Score: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected Systems
- debian•nodejs
all | all | all | all | < 24.17.0+dfsg+~cs24.13.2-1