Skip to main content

Get a free FHIR vulnerability scan, funded by Cantina.

Vulnerability disclosure

Embedded NUL bytes can silently rebind TLS authority

CVE-2026-48930

Affected product
Node.js
Severity
Medium
CVSS
Not scored
Weakness
CWE-626
Published

Disclosure summary

CVE-2026-48930 is a medium-severity CWE-626 vulnerability in Node.js. Embedded NUL bytes can silently rebind TLS authority. Cantina reproduced the behavior, verified its security impact, and coordinated disclosure with the affected maintainer.

Verification standard

Cantina publishes a disclosure only after reproducing the behavior, validating its security impact, and coordinating remediation with the affected project.