[CLSA-2026:1788261505] alt-nodejs20-nodejs: Fix of CVE-2026-58040
Type:
security
Severity:
Moderate
Release date:
2026-09-01 11:18:36 UTC
Description:
- CVE-2026-58040: https: bind identity checks to session reuse, so a request passing its own checkServerIdentity gets its own https.Agent pool name and neither resumes a cached TLS session nor reuses a keep-alive socket that was authenticated under different identity rules (incomplete-fix follow-up to CVE-2026-48934)
CVEs fixed:
Updated packages:
  • alt-nodejs20-nodejs-20.20.2-9.el10.x86_64.rpm
    sha:fb908fc58cdf8eb87e48a1bb04541fa1a353ba38c6f9d1980a1c5d06d9b95ae2
  • alt-nodejs20-nodejs-devel-20.20.2-9.el10.x86_64.rpm
    sha:86cfe83babc192f3fb7e654231b3246670f36322e461b08dc213fa92d44fbe17
  • alt-nodejs20-nodejs-docs-20.20.2-9.el10.noarch.rpm
    sha:41dd3652c87aa6abd12e86e08344df77d4c81a99990889e75578343b1b3cf334
  • alt-nodejs20-npm-10.8.2-20.20.2.9.el10.x86_64.rpm
    sha:3ff8e091bc7b884ed8e7d7a45c36282ca3702acd553429d38cfe040b6cf3d87e
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.