PT-2026-66409 · Openjs Foundation · Node.Js

CVE-2026-58040

·

Published

2026-07-30

·

Updated

2026-09-03

CVSS v3.1

6.3

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Node.js versions 22.x Node.js versions 24.x Node.js versions 26.x
Description An incomplete fix exists in the HTTPS Agent where TLS session reuse allows the system to skip hostname verification across identity policies.
Recommendations Update Node.js 22.x to the latest patched version. Update Node.js 24.x to version 24.18.1-1.1 or newer. Update Node.js 26.x to version 26.5.1-1.1 or newer.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-94349
BIT-NODE-2026-58040
BIT-NODE-MIN-2026-58040
CVE-2026-58040
ECHO-B33F-784D-6B12
OPENSUSE-SU-2026:11439-1
OPENSUSE-SU-2026:11440-1
OPENSUSE-SU-2026:21545-1
OPENSUSE-SU-2026:21546-1
SUSE-SU-2026:23130-1
SUSE-SU-2026:23131-1
SUSE-SU-2026:23154-1
SUSE-SU-2026:23155-1
SUSE-SU-2026:3520-1
SUSE-SU-2026:3521-1
SUSE-SU-2026:3557-1
SUSE-SU-2026:3929-1
SUSE-SU-2026:3930-1

Affected Products

Node.Js