CVE-2026-58040
Node.js Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-58040 is a Medium-severity vulnerability in Node.js where the HTTPS Agent's TLS session reuse mechanism skips hostname verification across different identity policies. It represents an incomplete fix of a prior vulnerability, CVE-2026-48934. The flaw affects Node.js 22.x (up to and including 22.23.1), 24.x (up to and including 24.18.0), and 26.x (up to and including 26.5.0). It was disclosed on July 30, 2026, as part of Node.js's July 2026 security release batch, and carries a CVSS v3.0 base score of 6.3 (Medium) (Node.js Advisory, GitHub Advisory).

Détails techniques

The root cause is an incomplete remediation of CVE-2026-48934: the Node.js HTTPS Agent, when reusing TLS sessions, fails to enforce hostname verification across different identity policies. This means a TLS session established for one identity (e.g., one set of client credentials or hostname) can be incorrectly reused for a request targeting a different identity, bypassing the expected hostname check. The attack requires network access and low-level privileges (PR:L), and exploitation complexity is rated High (AC:H), indicating specific conditions must be met — such as the attacker being able to influence or observe TLS session reuse behavior. No CWE classification has been formally assigned yet (Node.js Advisory, GitHub Advisory).

Impact

Successful exploitation allows an authenticated attacker with low privileges to read sensitive data intended for a different identity by reusing a TLS session that bypasses hostname verification. The confidentiality impact is rated High, while integrity and availability are unaffected. The changed scope (S:C) indicates that the impact can extend beyond the vulnerable component itself — for example, allowing access to resources or data belonging to other tenants or identities in multi-identity or mTLS-enabled deployments (Node.js Advisory, GitHub Advisory).

Atténuation et solutions de contournement

Node.js has released patched versions addressing CVE-2026-58040: v22.23.2, v24.18.1, and v26.5.1. Users should upgrade to the appropriate patched release for their release line as soon as possible. As an interim measure, administrators should review applications that use HTTPS with TLS session reuse and consider implementing additional network-level controls to restrict TLS session sharing across different security boundaries or identities (Node.js Advisory).

Réactions de la communauté

The vulnerability was covered by cybersecurity news outlets as part of broader reporting on Node.js's July 2026 security release, which addressed 11 vulnerabilities in total (CyberSecurityNews, CyberPress). Coverage noted that the release included both High and Medium severity fixes across all active Node.js release lines. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-58040 has been identified beyond standard vulnerability aggregator coverage.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté Node.js Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-54272MEDIUM6.9
  • Node.js logoNode.js
  • rust-std-static-wasm32-unknown-unknown
NonNonJul 27, 2026
CVE-2026-58043NONEN/A
  • Node.js logoNode.js
  • nodejs
NonOuiJul 30, 2026
CVE-2026-58040NONEN/A
  • Node.js logoNode.js
  • nodejs
NonOuiJul 30, 2026
CVE-2026-56850NONEN/A
  • Node.js logoNode.js
  • nodejs
NonOuiJul 30, 2026
CVE-2026-56847NONEN/A
  • Node.js logoNode.js
  • nodejs
NonOuiJul 30, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités