CVE-2026-58040: Medium severity OpenJS Foundation Node.js vulnerability
Published Jul 30, 2026
·Updated
An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js 22.x, 24.x, and 26.x.
Affected Software
4 affected componentsFixes available
OpenJS Foundation Node.js>=22.0.0<23.0.0
OpenJS Foundation Node.js>=24.0.0<25.0.0
OpenJS Foundation Node.js>=26.0.0<27.0.0
Microsoft azl3 nodejs 24.17.0-1<24.18.1-1
24.18.1-1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 24.18.1-1
Event History
Jul 30, 2026
CVE Published
via MITRE·06:02 AM
Data Sourced
via MITRE·06:02 AM
DescriptionSeverity
Data Sourced
via NVD·06:25 AM
DescriptionSeverityWeakness
Aug 7, 2026
Data Sourced
via Microsoft·08:04 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:04 AM
Affected Software
Updated
via Microsoft·08:04 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-58040?
CVE-2026-58040 has a medium severity rating of 6.3.
2
How do I fix CVE-2026-58040?
To fix CVE-2026-58040, upgrade to Node.js versions that are not affected by this vulnerability.
3
Which Node.js versions are impacted by CVE-2026-58040?
CVE-2026-58040 affects Node.js versions 22.x, 24.x, and 26.x.
4
What is the risk level associated with CVE-2026-58040?
CVE-2026-58040 is classified as having a risk level of 37.
5
What type of vulnerability is described in CVE-2026-58040?
CVE-2026-58040 is related to incomplete TLS session reuse and hostname verification issues in HTTPS Agent.