REDHAT-BUG-2493332: Medium severity OpenJS Foundation Node.js 22 vulnerability
Published Jun 26, 2026
·Updated
A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation.
This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
Affected Software
3 affected components
OpenJS Foundation Node.js 22=22
OpenJS Foundation Node.js 24=24
OpenJS Foundation Node.js 26=26
Event History
Jun 26, 2026
Data Sourced
via Red Hat·02:02 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2493332?
The severity of REDHAT-BUG-2493332 is medium, rated at 4.
2
How do I fix REDHAT-BUG-2493332?
To fix REDHAT-BUG-2493332, it is recommended to update to the latest patched version of Node.js 22, 24, or 26.
3
What is the impact of REDHAT-BUG-2493332?
The impact of REDHAT-BUG-2493332 is that an attacker can bypass certification validation due to a flaw in Node.js TLS host verification.
4
Which Node.js versions are affected by REDHAT-BUG-2493332?
REDHAT-BUG-2493332 affects all supported release lines of Node.js, specifically versions 22, 24, and 26.
5
Is REDHAT-BUG-2493332 a critical vulnerability?
No, REDHAT-BUG-2493332 is classified as a medium severity vulnerability, not critical.