TLS Session Reuse Vulnerability in Node.js Affects Multiple Versions
CVE-2026-58040

6.3MEDIUM

Key Information:

Vendor

Nodejs

Status
Vendor
CVE Published:
30 July 2026

What is CVE-2026-58040?

An incomplete fix has been identified in Node.js that allows TLS session reuse to bypass hostname verification across various identity policies. This flaw affects versions 22.x, 24.x, and 26.x, potentially compromising secure connections. Users are advised to upgrade to the latest versions to mitigate this security risk. For more information, please refer to the Node.js security release notes.

Affected Version(s)

node 22.23.1

node 24.18.0

node 26.5.0

References

CVSS V3.0

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.