[CLSA-2026:1788259912] alt-nodejs20-nodejs: Fix of CVE-2026-58040
Type:
security
Severity:
Moderate
Release date:
2026-09-01 10:52:03 UTC
Description:
- CVE-2026-58040: https: bind identity checks to session reuse, so a request passing its own checkServerIdentity gets its own https.Agent pool name and neither resumes a cached TLS session nor reuses a keep-alive socket that was authenticated under different identity rules (incomplete-fix follow-up to CVE-2026-48934)
CVEs fixed:
Updated packages:
  • alt-nodejs20-nodejs-20.20.2-9.el9.x86_64.rpm
    sha:fe55d79d48d9835b9830e0bb05b169995e40bdf3ebcd2a2bab624a0a1140a946
  • alt-nodejs20-nodejs-devel-20.20.2-9.el9.x86_64.rpm
    sha:a76d714d11557c9471ac45623ed6af7fc6c62bb39f57b96f273ab007f82e745a
  • alt-nodejs20-nodejs-docs-20.20.2-9.el9.noarch.rpm
    sha:0585d79dac879721586e3274f6d031bc7f7f502e15a179675b98f3cfdeae2207
  • alt-nodejs20-npm-10.8.2-20.20.2.9.el9.x86_64.rpm
    sha:5795d461e9903a3895c349e51e98954aba56ea2ef96538d6e4f47fbf9e20ee3d
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.