CVE-2026-58040
Published: August 1, 2026Last modified: August 3, 2026
Description
An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score | 6.3 |
| Attack Vector | NETWORK |
| Attack complexity | HIGH |
| Privileges required | LOW |
| User interaction | NONE |
| Scope | CHANGED |
| Confidentiality | HIGH |
| Integrity impact | NONE |
| Availability impact | NONE |
| Vector | CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N |
Status
| Product | Release | Package | Status |
|---|---|---|---|
| Alpaquita Linux | 25 LTS | nodejs | Fixed (22.23.2-r0) |
| Stream | nodejs | Fixed (24.18.1-r0) | |
| Hardened Containers | 25 LTS | nodejs | Fixed (22.23.2-r0) |
| Stream | nodejs | Fixed (24.18.1-r0) |