Node.js shipped security releases on June 18 for the 22, 24, and 26 lines: 22.23.0, 24.17.0, and 26.3.1. Twelve fixes, two high severity. One high is a crash on very large WebCrypto inputs. The other, and the one I want to talk about, is a mismatch in how a hostname with a Unicode dot separator is normalized, which let a certificate pass a wildcard depth check it should have failed.
It is not alone. Among the medium fixes are three more ways to fool identity checks in Transport Layer Security (TLS): case-sensitive matching in the mutual TLS (mTLS) server name context that allowed an authorization bypass, an embedded null in a hostname truncating what the verifier saw, and session reuse against a different server name skipping verification entirely.
Four hostname check bypasses in one release changes which traffic is in scope. The usual mental model is that TLS problems affect the public edge, and the edge is behind a load balancer that terminates TLS anyway. But mTLS between services is how a lot of internal authorization works, and these fixes are exactly there. If a service decides who it is talking to by the name on a certificate, this release is about that service.
One more line from the post is worth repeating: end of life versions are always affected and never get the fix. I think running an end of life Node line should be treated as an audit finding, not a backlog item.
Does your service-to-service auth depend on a hostname check, and did it get patched in June?
Photo source: https://photos.robertstowe.com/bermuda

