Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94349.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-94349
Upstream
  • CVE-2026-58040
Published
2026-07-30T06:25:55Z
Modified
2026-08-28T17:47:40Z
Summary
CVE-2026-58040 affecting package nodejs for versions less than 24.18.1-1
Details

An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934).

This vulnerability affects Node.js 22.x, 24.x, and 26.x.

References

Affected packages

Azure Linux:3 / nodejs

Package

Name
nodejs
Purl
pkg:rpm/azure-linux/nodejs

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
24.18.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-94349.json"