---
id: CVE-2026-48931
title: "A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 2…"
summary: "A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 2…"
severity: low
cvss: 3.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-367
vendor: nodejs
product: node.js
affected:
  - node.js = 22.22.3
  - node.js = 24.16.0
  - node.js = 26.3.0
published: '2026-06-22'
updated: '2026-07-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-48931'
references:
  - url: 'https://nodejs.org/en/blog/vulnerability/june-2026-security-releases'
    label: support@hackerone.com
  - url: 'http://www.openwall.com/lists/oss-security/2026/07/02/2'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/nodejs/node/issues/63989'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://jdstaerk.substack.com/p/nodejs-security-fix-silently-broke'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00345
epssPercentile: 0.28117
ingestedAt: '2026-07-03T13:02:27.816Z'
---

## Overview

A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request.

This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

## Affected

- `node.js = 22.22.3`
- `node.js = 24.16.0`
- `node.js = 26.3.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
