Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
nodejs node — A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request.
AV AC PR UI S C I A CVSS EPSS %ile KEV
N H N N U N L N 3.7 .0034 27.6 —
AFFECTED
Product Versions Fixed
node 22.22.3 – —
TIMELINE
May 26 Reserved by hackerone
Jun 22 EXPLOIT PUBLISHED — CVE-2026-48931 (nodejs node). Public exploit reference added.
Jun 22 Published (CNA: hackerone)
Description
A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request.
This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| May 26, 2026 | Reserved | Reserved by hackerone |
| June 22, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-48931 (nodejs node). Public exploit reference added. |
| June 22, 2026 | Published | Published (CNA: hackerone) |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| nodejs | node | — | 22.22.3 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-48931 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.