{"id":"SUSE-SU-2026:21181-1","summary":"Security update for nodejs24","details":"This update for nodejs24 fixes the following issues:\n\nUpdate to version 24.14.1.\n\nSecurity issues fixed:\n\n- CVE-2026-21717: trivially predictable hash collisions due to flaw in V8's string hashing mechanism allows for\n  performance degradation via a crafted request (bsc#1260494).\n- CVE-2026-21716: incomplete fix for CVE-2024-36137 allows promise-based FileHandle methods to be used to modify file\n  permissions and ownership on already-open file descriptors (bsc#1260462).\n- CVE-2026-21715: flaw in the Permission Model filesystem enforcement allows for file existence disclosure and\n  filesystem path enumeration via `fs.realpathSync.native()` (bsc#1260482).\n- CVE-2026-21714: memory leak in Node.js HTTP/2 server allows for resource exhaustion via `WINDOW_UPDATE` frames sent\n  on stream 0 (bsc#1260480).\n- CVE-2026-21713: timing side-channel due to flaw in Node.js HMAC verification allows for discovery of HMAC values and\n  potential MAC forgery (bsc#1260463).\n- CVE-2026-21712: assertion error caused by flaw in URL processing allows for a process crash via a URL with a\n  malformed IDN (bsc#1260460).\n- CVE-2026-21710: uncaught `TypeError` when handling HTTP requests allows for a process crash via requests with a\n  header named `__proto__` when the application accesses `req.headersDistinct` (bsc#1260455).\n- CVE-2026-21637: flaw in TLS error handling allows for resource exhaustion and crash when `pskCallback` or\n  `ALPNCallback` are in use (bsc#1256576).\n- CVE-2025-59464: memory leak allows for remote denial of service against applications processing TLS client\n  certificates (bsc#1256572).\n\nOther updates and bugfixes:\n\n- Version 24.14.0:\n  * async_hooks: add trackPromises option to createHook()\n  * build,deps: replace cjs-module-lexer with merve\n  * deps: add LIEF as a dependency\n  * events: repurpose events.listenerCount() to accept EventTargets\n  * fs: add ignore option to fs.watch\n  * http: add http.setGlobalProxyFromEnv()\n  * module: allow subpath imports that start with #/\n  * process: preserve AsyncLocalStorage in queueMicrotask only when needed\n  * sea: split sea binary manipulation code\n  * sqlite: enable defensive mode by default\n  * sqlite: add sqlite prepare options args\n  * src: add initial support for ESM in embedder API\n  * stream: add bytes() method to node:stream/consumers\n  * stream: do not pass readable.compose() output via Readable.from()\n  * test: use fixture directories for sea tests\n  * test_runner: add env option to run function\n  * test_runner: support expecting a test-case to fail\n  * util: add convertProcessSignalToExitCode utility\n  * For details, see https://nodejs.org/en/blog/release/v24.14.0\n\n","modified":"2026-04-22T20:09:47.579454Z","published":"2026-04-13T10:59:52Z","related":["CVE-2025-59464","CVE-2026-21637","CVE-2026-21710","CVE-2026-21712","CVE-2026-21713","CVE-2026-21714","CVE-2026-21715","CVE-2026-21716","CVE-2026-21717"],"upstream":["CVE-2025-59464","CVE-2026-21637","CVE-2026-21710","CVE-2026-21712","CVE-2026-21713","CVE-2026-21714","CVE-2026-21715","CVE-2026-21716","CVE-2026-21717"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202621181-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256572"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256576"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260455"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260460"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260462"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260463"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260480"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260482"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260494"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-59464"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21637"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21710"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21712"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21713"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21714"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21715"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21716"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21717"}],"affected":[{"package":{"name":"nodejs24","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/nodejs24&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.14.1-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"corepack24":"24.14.1-160000.1.1","nodejs24-devel":"24.14.1-160000.1.1","nodejs24-docs":"24.14.1-160000.1.1","nodejs24":"24.14.1-160000.1.1","npm24":"24.14.1-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21181-1.json"}},{"package":{"name":"nodejs24","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/nodejs24&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.14.1-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"nodejs24-devel":"24.14.1-160000.1.1","nodejs24-docs":"24.14.1-160000.1.1","nodejs24":"24.14.1-160000.1.1","npm24":"24.14.1-160000.1.1","corepack24":"24.14.1-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21181-1.json"}}],"schema_version":"1.7.5"}