node is vulnerable to Improper Certificate Validation
48
Medium Risk
An incomplete fix for CVE-2026-48934 left HTTPS Agent TLS session and connection reuse able to skip per-request hostname verification. When a request supplies a custom checkServerIdentity callback that was not also configured on the Agent itself, the Agent can still reuse a prior TLS session or keep-alive socket keyed only by host, so the custom identity check is never applied to the reused connection. An attacker who can redirect traffic after a session was established under a different identity policy may therefore bypass intended certificate hostname checks. The fix excludes per-request checkServerIdentity from session and connection reuse unless that option was set when constructing the Agent.
You are affected if you are using a version that falls within the vulnerable range.
node is vulnerable to Improper Certificate Validation in versions 25.0.0 - 26.5.0, 23.0.0 - 24.18.0 and 0.0.1 - 22.23.1.
Upgrade the node library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant