[CLSA-2026:1788261304] alt-nodejs20-nodejs: Fix of CVE-2026-58040
Type:
security
Severity:
Moderate
Release date:
2026-09-01 11:15:15 UTC
Description:
- CVE-2026-58040: https: bind identity checks to session reuse, so a request passing its own checkServerIdentity gets its own https.Agent pool name and neither resumes a cached TLS session nor reuses a keep-alive socket that was authenticated under different identity rules (incomplete-fix follow-up to CVE-2026-48934)
CVEs fixed:
Updated packages:
  • alt-nodejs20-nodejs-20.20.2-9.el7.x86_64.rpm
    sha:58f3983a50dfae4b0fdba4e6c15501cda0190c99ae9afb6113ca20ba2b3796f0
  • alt-nodejs20-nodejs-devel-20.20.2-9.el7.x86_64.rpm
    sha:e8216e33064b04224f20351a60a324019a410f899d451dc13bd8e807d202608f
  • alt-nodejs20-nodejs-docs-20.20.2-9.el7.noarch.rpm
    sha:d97de610ab5feca8acca9e5e4fe23754276b81302f297a76bb9a411a137fa3c3
  • alt-nodejs20-npm-10.8.2-20.20.2.9.el7.x86_64.rpm
    sha:9b3eb9906e0fdbaabc1af1505958a0fbe50cf53b8322c09f023eb85aee8f7640
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.