]> dgit.raspbian.org Git - nodejs.git/commit
tls: bind reusable sessions to authenticated host
authorMatteo Collina <hello@matteocollina.com>
Mon, 13 Apr 2026 07:53:48 +0000 (09:53 +0200)
committerBastien Roucariès <rouca@debian.org>
Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)
commit0c036408fab38e123f244b8261d3c3468e7355ed
tree1e13ee91f882ef50433ae67cdfee9ac04f526e3c
parent61f8acff81607d37c6ae348892a166a093eec50c
tls: bind reusable sessions to authenticated host

Backport-PR-URL: https://github.com/nodejs-private/node-private/pull/895
PR-URL: https://github.com/nodejs-private/node-private/pull/854
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
CVE-ID: CVE-2026-48934
Refs: https://hackerone.com/reports/3649802
origin: backport, https://github.com/nodejs/node/commit/fd890ba01d508ac111bbba302981d7fdf734d2ce
bug: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases#tls-host-identity-verification-bypass-via-session-reuse-with-different-servername-leads-to-unauthorized-connections-cve-2026-48934---medium

Gbp-Pq: Topic sec
Gbp-Pq: Name CVE-2026-48934.patch
lib/_tls_wrap.js