Release date:
2026-09-01 10:52:03 UTC
Description:
- CVE-2026-58040: https: bind identity checks to session reuse, so a request
passing its own checkServerIdentity gets its own https.Agent pool name and
neither resumes a cached TLS session nor reuses a keep-alive socket that was
authenticated under different identity rules (incomplete-fix follow-up to
CVE-2026-48934)
Updated packages:
-
alt-nodejs20-nodejs-20.20.2-9.el9.x86_64.rpm
sha:fe55d79d48d9835b9830e0bb05b169995e40bdf3ebcd2a2bab624a0a1140a946
-
alt-nodejs20-nodejs-devel-20.20.2-9.el9.x86_64.rpm
sha:a76d714d11557c9471ac45623ed6af7fc6c62bb39f57b96f273ab007f82e745a
-
alt-nodejs20-nodejs-docs-20.20.2-9.el9.noarch.rpm
sha:0585d79dac879721586e3274f6d031bc7f7f502e15a179675b98f3cfdeae2207
-
alt-nodejs20-npm-10.8.2-20.20.2.9.el9.x86_64.rpm
sha:5795d461e9903a3895c349e51e98954aba56ea2ef96538d6e4f47fbf9e20ee3d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.