{"id":"SUSE-SU-2026:4355-1","summary":"Security update for nodejs16","details":"This update for nodejs16 fixes the following issues:\n\n- CVE-2025-23085: memory leak when remote peer abruptly closes socket without sending GOAWAY notification (bsc#1236250).\n- CVE-2025-23166: improper error handling in async cryptographic operations crashes process (bsc#1243218).\n- CVE-2025-23167: llhttp: improper HTTP header block termination in llhttp (bsc#1243220).\n- CVE-2025-55131: timeout-based race conditions allow for allocations that contain leftover data from previous\n  operations and lead to exposure of in-process secrets (bsc#1256570).\n- CVE-2025-59465: malformed HTTP/2 HEADERS frame with invalid HPACK data can cause a crash due to an unhandled error\n  (bsc#1256573).\n- CVE-2025-59466: uncatchable 'Maximum call stack size exceeded' error when `async_hooks.createHook()` is enabled can\n  lead to crash (bsc#1256574).\n- CVE-2026-6733: undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response\n  delivery (bsc#1268479).\n- CVE-2026-11525: undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header\n  (bsc#1268481).\n- CVE-2026-12151: undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (bsc#1268482).\n- CVE-2026-15157: No validation of the type property of a duck-typed blob-like request body before using it as the\n  Content-Type header on the HTTP/1.1 dispatcher (bsc#1272958).\n- CVE-2026-21637: synchronous exceptions thrown during certain callbacks bypass the standard TLS error handling paths\n  and can cause a denial of service (bsc#1256576).\n- CVE-2026-21710: uncaught TypeError exception can cause a denial of service (bsc#1260455).\n- CVE-2026-21713: timing side-channel in HMAC verification via memcmp can lead to potential MAC forgery (bsc#1260463).\n- CVE-2026-21714: WINDOW_UPDATE frames on stream 0 can lead to memory leak (bsc#1260480).\n- CVE-2026-22036: undici: unbounded decompression chain in HTTP responses via Content-Encoding may lead to resource\n  exhaustion (bsc#1256848).\n- CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853).\n- CVE-2026-48618: Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to\n  resolver and verifier hostname normalization mismatch (bsc#1268593).\n- CVE-2026-48619: Unbounded memory growth in node:http2 clients via attacker-controlled ORIGIN frames (bsc#1268618).\n- CVE-2026-48928: Uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname\n  matching (bsc#1268605).\n- CVE-2026-48930: Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver\n  bindings (bsc#1268606).\n- CVE-2026-48931: HTTP Response Queue Poisoning via TOCTOU Race Condition in http.Agent (bsc#1268611).\n- CVE-2026-48933: Node.js WebCrypto AES Integer Overflow Leads to Remote Process Abort (bsc#1268592).\n- CVE-2026-48934: TLS host identity verification bypass via session reuse with different servername leads to\n  unauthorized connections (bsc#1268608).\n- CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555).\n- CVE-2026-56846: HTTP/2 retained headers can bypass maxSessionMemory limits (bsc#1272941).\n- CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942).\n- CVE-2026-56850: HTTPS Agent can reuse mTLS identities across PFX certificates (bsc#1272944).\n- CVE-2026-58040: HTTPS Agent session reuse can skip hostname verification (bsc#1272945).\n- CVE-2026-58042: dns.resolveAny() can abort on DNS responses with many A records (bsc#1272947).\n- CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951).\n- CVE-2026-58045: node:zlib sync APIs can crash on spoofed TypedArray length (bsc#1272948).\n","modified":"2026-09-29T09:15:08.730123833Z","published":"2026-09-28T08:55:58Z","related":["CVE-2025-23085","CVE-2025-23166","CVE-2025-23167","CVE-2025-55131","CVE-2025-59465","CVE-2025-59466","CVE-2026-11525","CVE-2026-12151","CVE-2026-15157","CVE-2026-21637","CVE-2026-21710","CVE-2026-21713","CVE-2026-21714","CVE-2026-22036","CVE-2026-27135","CVE-2026-48618","CVE-2026-48619","CVE-2026-48928","CVE-2026-48930","CVE-2026-48931","CVE-2026-48933","CVE-2026-48934","CVE-2026-48937","CVE-2026-56846","CVE-2026-56848","CVE-2026-56850","CVE-2026-58040","CVE-2026-58042","CVE-2026-58044","CVE-2026-58045","CVE-2026-6733"],"upstream":["CVE-2025-23085","CVE-2025-23166","CVE-2025-23167","CVE-2025-55131","CVE-2025-59465","CVE-2025-59466","CVE-2026-11525","CVE-2026-12151","CVE-2026-15157","CVE-2026-21637","CVE-2026-21710","CVE-2026-21713","CVE-2026-21714","CVE-2026-22036","CVE-2026-27135","CVE-2026-48618","CVE-2026-48619","CVE-2026-48928","CVE-2026-48930","CVE-2026-48931","CVE-2026-48933","CVE-2026-48934","CVE-2026-48937","CVE-2026-56846","CVE-2026-56848","CVE-2026-56850","CVE-2026-58040","CVE-2026-58042","CVE-2026-58044","CVE-2026-58045","CVE-2026-6733"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2026/suse-su-20264355-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1236250"},{"type":"REPORT","url":"https://bugzilla.suse.com/1243218"},{"type":"REPORT","url":"https://bugzilla.suse.com/1243220"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256570"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256573"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256574"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256576"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256848"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259853"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260455"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260463"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260480"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268479"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268481"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268482"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268555"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268592"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268593"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268605"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268606"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268608"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268611"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268618"},{"type":"REPORT","url":"https://bugzilla.suse.com/1269825"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272941"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272942"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272944"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272945"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272947"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272948"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272951"},{"type":"REPORT","url":"https://bugzilla.suse.com/1272958"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-23085"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-23166"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-23167"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-55131"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-59465"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2025-59466"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11525"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12151"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-15157"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21637"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21710"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21713"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21714"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-22036"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27135"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48618"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48619"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48928"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48930"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48931"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48933"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48934"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48937"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56846"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56848"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-56850"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58040"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58042"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58044"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-58045"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6733"}],"affected":[{"package":{"name":"nodejs16","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS","purl":"pkg:rpm/suse/nodejs16&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"16.20.2-150400.3.42.1"}]}],"ecosystem_specific":{"binaries":[{"nodejs16-devel":"16.20.2-150400.3.42.1","nodejs16-docs":"16.20.2-150400.3.42.1","npm16":"16.20.2-150400.3.42.1","nodejs16":"16.20.2-150400.3.42.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4355-1.json"}},{"package":{"name":"nodejs16","ecosystem":"SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS","purl":"pkg:rpm/suse/nodejs16&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"16.20.2-150400.3.42.1"}]}],"ecosystem_specific":{"binaries":[{"nodejs16":"16.20.2-150400.3.42.1","nodejs16-devel":"16.20.2-150400.3.42.1","nodejs16-docs":"16.20.2-150400.3.42.1","npm16":"16.20.2-150400.3.42.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4355-1.json"}},{"package":{"name":"nodejs16","ecosystem":"SUSE:Linux Enterprise Server 15 SP4-LTSS","purl":"pkg:rpm/suse/nodejs16&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"16.20.2-150400.3.42.1"}]}],"ecosystem_specific":{"binaries":[{"npm16":"16.20.2-150400.3.42.1","nodejs16":"16.20.2-150400.3.42.1","nodejs16-devel":"16.20.2-150400.3.42.1","nodejs16-docs":"16.20.2-150400.3.42.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4355-1.json"}},{"package":{"name":"nodejs16","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 15 SP4","purl":"pkg:rpm/suse/nodejs16&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"16.20.2-150400.3.42.1"}]}],"ecosystem_specific":{"binaries":[{"nodejs16":"16.20.2-150400.3.42.1","nodejs16-devel":"16.20.2-150400.3.42.1","nodejs16-docs":"16.20.2-150400.3.42.1","npm16":"16.20.2-150400.3.42.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4355-1.json"}}],"schema_version":"1.9.0"}