tls: bind reusable sessions to authenticated host
Backport-PR-URL: https://github.com/nodejs-private/node-private/pull/895
PR-URL: https://github.com/nodejs-private/node-private/pull/854
Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
CVE-ID: CVE-2026-48934
Refs: https://hackerone.com/reports/
3649802
origin: backport, https://github.com/nodejs/node/commit/
fd890ba01d508ac111bbba302981d7fdf734d2ce
bug: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases#tls-host-identity-verification-bypass-via-session-reuse-with-different-servername-leads-to-unauthorized-connections-cve-2026-48934---medium
Gbp-Pq: Topic sec
Gbp-Pq: Name CVE-2026-48934.patch