What is CVE-2026-58041?
CVE-2026-58041 is a flaw in Node.js node:sqlite that allows a stale StatementSyncIterator from DatabaseSync#createTagStore() to continue executing a cached prepared statement after reset and rebinding. This affects users relying on TagStore functionality. Users should update Node.js to the patched version.
Azərbaycanca: CVE-2026-58041 Node.js node:sqlite modulunda köhnəlmiş StatementSyncIterator vasitəsilə cached prepared statement-in sıfırlandıqdan və yeni parametrlərlə yenidən bağlandıqdan sonra icrasına imkan verən boşluqdur. Bu, DatabaseSync#createTagStore() ilə yaradılmış iteratorlara təsir edir. İstifadəçilər Node.js-in yenilənmiş versiyasına keçməlidirlər.
FAQ2
Which Node.js module is affected by CVE-2026-58041?
This vulnerability affects the node:sqlite module of Node.js.
What should users do to protect against CVE-2026-58041?
Users should update Node.js to the patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.