SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-58040

MEDIUM · CVSS 6.3 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-30 · Last synced 2026-08-29

CyberRota Analysis

AI-Generated

Node.js versions 22.x, 24.x, and 26.x are vulnerable due to an incomplete fix that allows the HTTPS Agent TLS session reuse to bypass hostname verification across identity policies. This could lead to potential man-in-the-middle attacks, compromising the integrity and confidentiality of data transmitted over HTTPS. Organizations using these Node.js versions should prioritize applying the necessary patches to mitigate this security risk.

CVE
CVE-2026-58040
Severity
MEDIUM
CVSS
6.3
EPSS
0.27%

Original NVD Description

An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.