Release date:
2026-09-01 12:46:16 UTC
Description:
- CVE-2026-58040: https: bind identity checks to session reuse, so a request
passing its own checkServerIdentity gets its own https.Agent pool name and
neither resumes a cached TLS session nor reuses a keep-alive socket that was
authenticated under different identity rules (incomplete-fix follow-up to
CVE-2026-48934)
Updated packages:
-
alt-nodejs20-nodejs-20.20.2-9.el8.x86_64.rpm
sha:672583bdde6e81dcd24d39fb21a29056d1c48639552c228ab4bbd3e0e9c45d23
-
alt-nodejs20-nodejs-devel-20.20.2-9.el8.x86_64.rpm
sha:b0cf926e6cbf2c3e03b1e9ae12365ec3240ce8ecd618a46862badc5a70c66bcd
-
alt-nodejs20-nodejs-docs-20.20.2-9.el8.noarch.rpm
sha:1e4394e3a8a7af8eb35743a3693e1d6384a827d92523078c71b63868a53a090f
-
alt-nodejs20-npm-10.8.2-20.20.2.9.el8.x86_64.rpm
sha:b3b5e5a713f3c9e8bdf5bed454afe5a8c7bafde8145550682e286935e3af044a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.