CVE-2026-58040

Updated on 30 Jul 2026

Severity

6.3 Medium severity

Details

CVSS score
6.3
CVSS vector
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

Overview

About vulnerability

An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934).

This vulnerability affects Node.js 22.x, 24.x, and 26.x.

Details

Affected packages:
alt-nodejs18 @ 18 (+89 more)

Fixes