VYPR
Medium severity6.3NVD Advisory· Published Jul 30, 2026· Updated Sep 3, 2026

CVE-2026-58040

CVE-2026-58040

Description

An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934).

This vulnerability affects Node.js 22.x, 24.x, and 26.x.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7

Patches

Vulnerability mechanics

References

1

News mentions

2