A vulnerability was found in Node.js up to 22.23.1/24.18.0/26.5.0. It has been classified as critical. The impacted element is an unknown function of the component HTTP Client. The manipulation leads to improper synchronization.

This vulnerability is listed as CVE-2026-58044. The attack may be initiated remotely. There is no available exploit.