{"id":"SUSE-SU-2026:3520-1","summary":"Security update for nodejs24","details":"This update for nodejs24 fixes the following issues:\n\nUpdate to 24.18.1.\n\n- CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust-\n  boundary checks (bsc#1272882).\n- CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941).\n- CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949).\n- CVE-2026-56848: HTTP/2 re-entrant send can cause heap use-after-free (bsc#1272942).\n- CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944).\n- CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950).\n- CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945).\n- CVE-2026-58041: `node:sqlite` `SQLTagStore` iterator replay can re-execute writes (bsc#1272946).  \n- CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many A records (bsc#1272947).\n- CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943).\n- CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951).\n- CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948).\n\nOther updates and bugfixes:\n\n- Version 24.18.0:\n  * fix: severe regression in security update 24.17 of nodejs24 (bsc#1269825)\n  * doc: update blockList stability status to release candidate\n  * fs: support caller-supplied readFile() buffers\n  * http: close pre-request sockets in closeIdleConnections\n  * loader: implement package maps\n  * net: support TCP_KEEPINTVL and TCP_KEEPCNT in setKeepAlive\n  * tls: add certificateCompression option\n  * vfs: dispatch node:fs/promises to mounted VFS instances\n  * vfs: add minimal node:vfs subsystem\n","modified":"2026-08-07T10:02:34.426999268Z","published":"2026-08-06T11:31:16Z","related":["CVE-2026-54272","CVE-2026-56846","CVE-2026-56847","CVE-2026-56848","CVE-2026-56850","CVE-2026-58039","CVE-2026-58040","CVE-2026-58041","CVE-2026-58042","CVE-2026-58043","CVE-2026-58044","CVE-2026-58045"],"upstream":["CVE-2026-54272","CVE-2026-56846","CVE-2026-56847","CVE-2026-56848","CVE-2026-56850","CVE-2026-58039","CVE-2026-58040","CVE-2026-58041","CVE-2026-58042","CVE-2026-58043","CVE-2026-58044","CVE-2026-58045"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20263520-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268097"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269825"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272882"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272941"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272942"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272943"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272944"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272945"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272946"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272947"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272948"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272949"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272950"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272951"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-54272"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56846"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56847"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56848"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56850"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58039"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58040"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58041"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58042"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58043"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58044"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58045"}],"affected":[{"package":{"name":"nodejs24","ecosystem":"SUSE:Linux Enterprise Module for Web and Scripting 15 SP7","purl":"pkg:rpm/suse/nodejs24&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP7"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"24.18.1-150700.15.16.1"}]}],"ecosystem_specific":{"binaries":[{"nodejs24-devel":"24.18.1-150700.15.16.1","nodejs24-docs":"24.18.1-150700.15.16.1","npm24":"24.18.1-150700.15.16.1","nodejs24":"24.18.1-150700.15.16.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3520-1.json"}}],"schema_version":"1.8.0"}