CVE-2026-58041

Aliases:ALPINE-CVE-2026-58041UBUNTU-CVE-2026-58041DEBIAN-CVE-2026-58041CGA-2952-935m-xv93CGA-9wvr-5vf8-r8hxCGA-jh5r-g638-2q4pCGA-rg6h-865r-9pj4
Awaiting Analysis
Published: 04 Aug 2026, 00:49
Last modified:04 Aug 2026, 15:04

Vulnerability Summary

Overall Risk (default)
low
21/100
CVSS Score
5.3 MEDIUM
v3.0 (cve.org)
EPSS Score
0.25% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

04 Aug 2026, 00:49
Published
Vulnerability first disclosed
04 Aug 2026, 15:04
Last Modified
Vulnerability information updated

Description

A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and rebound with new parameters. SQLTagStore resets cached statements using sqlite3_reset() directly, bypassing the iterator invalidation mechanism introduced for StatementSync in recent releases This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

CVSS Metrics

  • v3.0MEDIUMScore: 5.3CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

EPSS Trends

Current EPSS score: 0.25% Percentile: 17%

Techniques & Countermeasures

  • CWE-367Time-of-check Time-of-use (TOCTOU) Race Condition

    The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

Affected Systems

  • alpinenodejs

    < 24.18.1-r0 | < 24.18.1-r0

  • chainguardnodejs-20

    all

  • chainguardnodejs-25

    all

  • wolfinodejs-20

    all

  • wolfinodejs-25

    all

  • debiannodejs

    all | all | all | all | < 24.19.0+dfsg+~cs24.13.3-1

  • ubuntunodejs

    all | all | all

  • nodejsnode

    22.23.1 | 24.18.0 | 26.5.0

References (6)