Security Advisory

CVE-2026-48931

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-22 18:59:30
Last updated 2026-07-03 00:32:38
Assigner hackerone
CVSS score 3.7
State PUBLISHED

Description

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.