Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Node.js Security Update Addresses Critical Vulnerabilities

Node.js Security Update Addresses Critical Vulnerabilities

Posted on June 19, 2026 By CWS

Node.js has issued a significant security update to address 12 vulnerabilities, including two high-severity flaws that pose risks of authentication bypass and denial-of-service (DoS) attacks. These updates are essential for maintaining the integrity and security of applications relying on Node.js.

Critical Vulnerabilities Revealed

The update impacts Node.js versions 22.x, 24.x, and 26.x, with new patches available as of June 18, 2026. Among the critical issues is CVE-2026-48618, which involves improper Unicode dot separator handling in TLS hostname verification. This vulnerability can lead to mismatches between hostname normalization by the resolver and verifier, potentially allowing attackers to bypass TLS wildcard-based authentication.

Another high-severity vulnerability, CVE-2026-48933, affects the WebCrypto API. It arises from an integer overflow when the subtle.encrypt() function processes inputs that are multiples of 2 GiB, risking remote process crashes and DoS conditions.

Additional Vulnerabilities Addressed

Further vulnerabilities include CVE-2026-48934, which allows TLS host identity verification bypass via session reuse with a different server name. Additionally, CVE-2026-48928 involves case-sensitive hostname matching, potentially bypassing mutual TLS (mTLS) authorization in multi-context deployments.

Node.js also resolved CVE-2026-48930, where embedded null bytes in hostnames could lead to silent authority rebinding. Another concern, CVE-2026-48619, exposes HTTP/2 clients to unbounded memory growth due to attacker-controlled ORIGIN frames, risking resource exhaustion.

Importance of Timely Updates

Security experts emphasize the importance of upgrading to the latest patched versions, such as Node.js v22.23.0, v24.17.0, and v26.3.1, to mitigate these vulnerabilities. The updates also include dependency updates for components like llhttp 9.4.2, nghttp2 1.69.0, and OpenSSL 3.5.7.

This release highlights the critical nature of maintaining current software environments, especially for platforms like Node.js, which are integral to modern web applications and APIs. It serves as a reminder of the ongoing need for vigilance in cybersecurity practices.

End-of-life versions remain susceptible to these vulnerabilities and should be avoided in production settings. Stay informed by following us on Google News, LinkedIn, and X for more updates.

Cyber Security News Tags:authentication bypass, CVE, Cybersecurity, dependency updates, DoS attacks, HTTP2, Node.js, OpenSSL, Patch, runtime environment, security update, software update, TLS, Vulnerabilities, WebCrypto API

Post navigation

Previous Post: Klue Supply Chain Breach Affects Cybersecurity Giants
Next Post: FortiBleed Campaign Compromises 86,000 Fortinet Devices

Related Posts

Microsoft Warns Windows Systems May Enter BitLocker Recovery After October 2025 Updates Microsoft Warns Windows Systems May Enter BitLocker Recovery After October 2025 Updates Cyber Security News
New Stealth Malware Campaign Targets Key Sectors New Stealth Malware Campaign Targets Key Sectors Cyber Security News
Italian Adviser Becomes Latest Target in Expanding Paragon Graphite Spyware Surveillance Case Italian Adviser Becomes Latest Target in Expanding Paragon Graphite Spyware Surveillance Case Cyber Security News
Unit 42 Unveils Attribution Framework to Classify Threat Actors Based on Activity Unit 42 Unveils Attribution Framework to Classify Threat Actors Based on Activity Cyber Security News
New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack Users Cyber Security News
ChatGPT Hacked Using Custom GPTs Exploiting SSRF Vulnerability to Expose Secrets ChatGPT Hacked Using Custom GPTs Exploiting SSRF Vulnerability to Expose Secrets Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI’s Role in Transforming Threat Management Strategies
  • E-commerce Sites Targeted by Malware Through Okendo Widget
  • CryptoBandits Malware Abuses Tor for RCE and Data Theft
  • Access Control: The New Challenge of Shadow AI
  • Sophisticated Crypto Clipper Malware Targets USB Drives

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI’s Role in Transforming Threat Management Strategies
  • E-commerce Sites Targeted by Malware Through Okendo Widget
  • CryptoBandits Malware Abuses Tor for RCE and Data Theft
  • Access Control: The New Challenge of Shadow AI
  • Sophisticated Crypto Clipper Malware Targets USB Drives

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark