Executive brief
A security flaw in Node.js can allow unauthorized users to bypass identity checks in specific server configurations. This occurs when a server is set up to handle multiple secure identities (mTLS) and fails to correctly match incoming requests to the appropriate security policy due to how it handles uppercase letters in web addresses. This could allow a user to gain access to data or services they are not authorized to use.
Technical details
A vulnerability exists in Node.js where uppercase SNI (Server Name Indication) context matching is performed inconsistently. In multi-context mutual TLS (mTLS) configurations, the hostname matching logic is case-sensitive, whereas the resolver or other components may treat hostnames differently. This mismatch allows an attacker to bypass intended trust policies by providing a hostname that fails to match the specific security context required for authorization. The issue affects Node.js versions 22, 24, and 26, and has been addressed in security releases v22.23.0, v24.17.0, and v26.3.1.
Affected products
- Node.js Node.js 22.x, 24.x, 26.x
Timeline
- 2026-06-18: patched: Security releases v22.23.0, v24.17.0, and v26.3.1 made available.
- 2026-06-26: disclosed: CVE-2026-48928 published.