cbcvebase.
CVE-2026-58041
published 2026-08-04

CVE-2026-58041: A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared…

PriorityP429medium5.3CVSS 3.0
AVNACHPRNUIRSUCNIHAN
EPSS
0.32%
24.9th percentile
A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepared statement after it has been reset and rebound with new parameters. SQLTagStore resets cached statements using sqlite3_reset() directly, bypassing the iterator invalidation mechanism introduced for StatementSync in recent releases This vulnerability affects Node.js **22.x**, **24.x**, and **26.x**.

Affected

5 ranges
VendorProductVersion rangeFixed in
nodejsnode22.23.1 – 22.23.1
nodejsnode24.18.0 – 24.18.0
nodejsnode26.5.0 – 26.5.0
nodejs_22nodejs
nodejs_24nodejs

CVSS provenance

nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.