CVE-2026-58044: Low severity Node.js Node.js 22 vulnerability
A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild outbound headers from the visible IncomingMessage headers while piping the original body to a reused backend connection. Node.js can omit headers beyond maxHeadersCount / maxHeaderPairs from req.headers, req.rawHeaders, and req.headersDistinct, while still using those omitted headers internally for HTTP message framing. In particular, Content-Length can be hidden from userland while the request body is still delivered. This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58044?
The severity of CVE-2026-58044 is classified as low, rated at 3.7.
How do I fix CVE-2026-58044?
To mitigate CVE-2026-58044, it's recommended to upgrade to the latest version of Node.js that addresses this vulnerability.
Who is affected by CVE-2026-58044?
CVE-2026-58044 affects applications using Node.js 22 and 24 that utilize HTTP clients, particularly those functioning as forwarding proxies.
What type of vulnerability is CVE-2026-58044?
CVE-2026-58044 is a request desynchronization vulnerability occurring in Node.js HTTP clients.
What are the potential consequences of CVE-2026-58044?
The potential consequences of CVE-2026-58044 include incomplete request header reconstruction, which may affect application behavior and performance.