Node.js embedded-NUL hostname authority rebinding flaw
CVE-2026-48930 is a medium-severity Node.js TLS/hostname handling vulnerability in which embedded null bytes in hostnames are not handled safely across hostname processing and resolver bindings. According to the provided context, an embedded-NUL hostname can be truncated in C-string-based resolver bindings, causing the effective hostname used by lower-level resolution logic to differ from the full hostname seen by higher-level validation logic. This mismatch can result in silent authority rebinding during hostname handling and verification. The issue affects supported Node.js 22.x, 24.x, and 26.x release lines prior to the fixed releases referenced in the June 2026 security updates.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Recent activity
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A medium-severity Node.js hostname handling flaw where embedded null bytes can cause silent authority rebinding due to truncation behavior.
A medium-severity Node.js flaw involving embedded-NUL hostnames that leads to silent authority rebinding.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.