{"id":"MGASA-2026-0359","summary":"Updated nodejs packages fix security vulnerabilities","details":"http2: retain header memory in session accounting. (CVE-2026-56846)\nhttp2: defer rst stream while in scope. (CVE-2026-56848)\npermission: avoid granting radix split nodes. (CVE-2026-58043)\nhttps: distinguish PFX object-array agent keys. (CVE-2026-56850)\nhttps: bind identity checks to session reuse. (CVE-2026-58040)\ndns: handle large resolveAny address replies. (CVE-2026-58042)\nzlib: throw on out-of-bounds write buffers. (CVE-2026-58045)\npermission: enforce fs write permission for trace events.\n(CVE-2026-56847)\npermission: check final report output path. (CVE-2026-58039)\nhttp: reject requests exceeding max header count. (CVE-2026-58044)\n","modified":"2026-09-01T03:27:37.640498154Z","published":"2026-09-01T03:06:53Z","upstream":["CVE-2026-56846","CVE-2026-56847","CVE-2026-56848","CVE-2026-56850","CVE-2026-58039","CVE-2026-58040","CVE-2026-58042","CVE-2026-58043","CVE-2026-58044","CVE-2026-58045"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0359.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36201"},{"type":"WEB","url":"https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"},{"type":"WEB","url":"https://nodejs.org/en/blog/release/v22.23.2"}],"affected":[{"package":{"name":"nodejs","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/nodejs?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"22.23.2-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0359.json"}},{"package":{"name":"nodejs","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/nodejs?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"22.23.2-1.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0359.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}