The Node.js project released security updates across its supported 22.x, 24.x, and 26.x lines to fix 12 vulnerabilities, including two high-severity issues that prompted calls for immediate patching. The most serious bugs are CVE-2026-48618, a TLS hostname verification flaw caused by improper handling of Unicode dot separators that can lead to authentication bypass, and CVE-2026-48933, a WebCrypto AES integer overflow that can crash processes and enable remote denial-of-service. The releases were announced for all active Node.js lines through the project’s coordinated June security update process and public notices on the oss-sec mailing list.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
A new Node.js issue disclosed that tls.checkServerIdentity() no longer matches IPv6 IP-Address SANs, identifying the behavior as a regression in v24.17.0. This is a separate technical development from the June 18 security release and subsequent advisory.
On 2026-06-22, the Canadian Centre for Cyber Security published advisory AV26-624 about the Node.js security releases issued on June 18. The notice identified affected versions in the 22.x, 24.x, and 26.x lines and urged users and administrators to review the release information and apply the updates.
On June 18, 2026, Node.js released security updates for its supported 22.x, 24.x, and 26.x release lines to address 12 vulnerabilities. Reported issues included high-severity flaws such as CVE-2026-48618 and CVE-2026-48933, along with additional fixes affecting TLS, HTTP/2, proxy handling, permissions, and related components.
An earlier Node.js notice stated that new versions of all supported release lines were intended to be released on or shortly after June 17, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
10 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcemy.f5.com
Open sourcemy.f5.com
Open sourcecyber.gc.ca
Open sourcesecurityonline.info
Open sourceseclists.org
Open sourceseclists.org
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.