{"id":"SUSE-SU-2026:23155-1","summary":"Security update for nodejs24","details":"This update for nodejs24 fixes the following issues:\n\nUpdate to 24.18.1.\n\n- CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust-\n  boundary checks (bsc#1272882).\n- CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941).\n- CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949).\n- CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942).\n- CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944).\n- CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950).\n- CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945).\n- CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many A records (bsc#1272947).\n- CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943).\n- CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951).\n- CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948).\n","modified":"2026-08-14T18:24:04.901824213Z","published":"2026-08-10T08:46:10Z","related":["CVE-2026-54272","CVE-2026-56846","CVE-2026-56847","CVE-2026-56848","CVE-2026-56850","CVE-2026-58039","CVE-2026-58040","CVE-2026-58041","CVE-2026-58042","CVE-2026-58043","CVE-2026-58044","CVE-2026-58045"],"upstream":["CVE-2026-54272","CVE-2026-56846","CVE-2026-56847","CVE-2026-56848","CVE-2026-56850","CVE-2026-58039","CVE-2026-58040","CVE-2026-58041","CVE-2026-58042","CVE-2026-58043","CVE-2026-58044","CVE-2026-58045"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-202623155-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272882"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272941"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272942"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272943"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272944"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272945"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272946"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272947"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272948"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272949"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272950"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272951"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-54272"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56846"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56847"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56848"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56850"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58039"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58040"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58041"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58042"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58043"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58044"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58045"}],"affected":[{"package":{"name":"nodejs24","ecosystem":"SUSE:Linux Enterprise Server 16.0","purl":"pkg:rpm/suse/nodejs24&distro=SUSE%20Linux%20Enterprise%20Server%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.18.1-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"npm24":"24.18.1-160000.1.1","corepack24":"24.18.1-160000.1.1","nodejs24":"24.18.1-160000.1.1","nodejs24-devel":"24.18.1-160000.1.1","nodejs24-docs":"24.18.1-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23155-1.json"}},{"package":{"name":"nodejs24","ecosystem":"SUSE:Linux Enterprise Server for SAP applications 16.0","purl":"pkg:rpm/suse/nodejs24&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.18.1-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"corepack24":"24.18.1-160000.1.1","nodejs24":"24.18.1-160000.1.1","nodejs24-devel":"24.18.1-160000.1.1","nodejs24-docs":"24.18.1-160000.1.1","npm24":"24.18.1-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:23155-1.json"}}],"schema_version":"1.9.0"}