Medium severity5.3NVD Advisory· Published Aug 4, 2026· Updated Aug 4, 2026
CVE-2026-58041
CVE-2026-58041
Description
A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and rebound with new parameters. SQLTagStore resets cached statements using sqlite3_reset() directly, bypassing the iterator invalidation mechanism introduced for StatementSync in recent releases
This vulnerability affects Node.js 22.x, 24.x, and 26.x.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: 22.x, 24.x, 26.x
- osv-coords2 versionspkg:rpm/opensuse/nodejs24&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/nodejs26&distro=openSUSE%20Tumbleweed
< 24.18.1-1.1+ 1 more
- (no CPE)range: < 24.18.1-1.1
- (no CPE)range: < 26.5.1-1.1
Patches
Vulnerability mechanics
References
1News mentions
1- Node.js Fixes 11 Security Flaws That Can Crash Servers and Break Filesystem RestrictionsCyber Security News · Jul 30, 2026