[CLSA-2026:1788266766] alt-nodejs20-nodejs: Fix of CVE-2026-58040
Type:
security
Severity:
Moderate
Release date:
2026-09-01 12:46:16 UTC
Description:
- CVE-2026-58040: https: bind identity checks to session reuse, so a request passing its own checkServerIdentity gets its own https.Agent pool name and neither resumes a cached TLS session nor reuses a keep-alive socket that was authenticated under different identity rules (incomplete-fix follow-up to CVE-2026-48934)
CVEs fixed:
Updated packages:
  • alt-nodejs20-nodejs-20.20.2-9.el8.x86_64.rpm
    sha:672583bdde6e81dcd24d39fb21a29056d1c48639552c228ab4bbd3e0e9c45d23
  • alt-nodejs20-nodejs-devel-20.20.2-9.el8.x86_64.rpm
    sha:b0cf926e6cbf2c3e03b1e9ae12365ec3240ce8ecd618a46862badc5a70c66bcd
  • alt-nodejs20-nodejs-docs-20.20.2-9.el8.noarch.rpm
    sha:1e4394e3a8a7af8eb35743a3693e1d6384a827d92523078c71b63868a53a090f
  • alt-nodejs20-npm-10.8.2-20.20.2.9.el8.x86_64.rpm
    sha:b3b5e5a713f3c9e8bdf5bed454afe5a8c7bafde8145550682e286935e3af044a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.