CVE-2026-58040Disclosure

LOWCVSS 6.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-297

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-18: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-18: 108-18
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • CyStack@CyStackSecurity
    Disclosure

    CVE-2026-58040: TLS session reuse in Node.js's HTTPS Agent can skip hostname verification. An incomplete fix for CVE-2026-48934. Reuse a session across different identity policies and the certificate check for the new host gets bypassed. Affects 22.x, 24.x, 26.x. Patched in v22.23.2, v24.18.1, v26.5.1. Found by a CyStack researcher. Details at https://cystack.net/disclosures

    Post summary

    The post announces that CVE-2026-58040 in Node.js allows TLS session reuse to skip hostname verification, lists affected and patched versions, and references a CyStack disclosure page; it also mentions an incomplete fix for CVE-2026-48934.

    0100058
    3.7K followersView on X

Explore more