Release date:
2026-09-01 11:18:36 UTC
Description:
- CVE-2026-58040: https: bind identity checks to session reuse, so a request
passing its own checkServerIdentity gets its own https.Agent pool name and
neither resumes a cached TLS session nor reuses a keep-alive socket that was
authenticated under different identity rules (incomplete-fix follow-up to
CVE-2026-48934)
Updated packages:
-
alt-nodejs20-nodejs-20.20.2-9.el10.x86_64.rpm
sha:fb908fc58cdf8eb87e48a1bb04541fa1a353ba38c6f9d1980a1c5d06d9b95ae2
-
alt-nodejs20-nodejs-devel-20.20.2-9.el10.x86_64.rpm
sha:86cfe83babc192f3fb7e654231b3246670f36322e461b08dc213fa92d44fbe17
-
alt-nodejs20-nodejs-docs-20.20.2-9.el10.noarch.rpm
sha:41dd3652c87aa6abd12e86e08344df77d4c81a99990889e75578343b1b3cf334
-
alt-nodejs20-npm-10.8.2-20.20.2.9.el10.x86_64.rpm
sha:3ff8e091bc7b884ed8e7d7a45c36282ca3702acd553429d38cfe040b6cf3d87e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.