Description

A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

Severity (CVSS)

Base score7.7
SeverityHigh
VersionCVSS 3.0
VectorCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Provided byCNA

Weaknesses

  • CWE-176 — CWE-176 Improper Handling of Unicode Encoding

Affected products

VendorProductVersions
nodejsnode22.22.3 to <=22.22.3; 24.16.0 to <=24.16.0; 26.3.0 to <=26.3.0

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 26 Jun 2026 07:05 UTC.