{"schema_version":"1.7.5","id":"openSUSE-SU-2026:21058-1","published":"2026-06-25T13:50:58Z","modified":"2026-06-30T18:24:37.973780169Z","related":["CVE-2026-11525","CVE-2026-12151","CVE-2026-21637","CVE-2026-21710","CVE-2026-21713","CVE-2026-21714","CVE-2026-21715","CVE-2026-21716","CVE-2026-21717","CVE-2026-27135","CVE-2026-40170","CVE-2026-42338","CVE-2026-48615","CVE-2026-48617","CVE-2026-48618","CVE-2026-48619","CVE-2026-48928","CVE-2026-48930","CVE-2026-48931","CVE-2026-48933","CVE-2026-48934","CVE-2026-48935","CVE-2026-48937","CVE-2026-6733","CVE-2026-9496","CVE-2026-9679"],"upstream":["CVE-2026-11525","CVE-2026-12151","CVE-2026-21637","CVE-2026-21710","CVE-2026-21713","CVE-2026-21714","CVE-2026-21715","CVE-2026-21716","CVE-2026-21717","CVE-2026-27135","CVE-2026-40170","CVE-2026-42338","CVE-2026-48615","CVE-2026-48617","CVE-2026-48618","CVE-2026-48619","CVE-2026-48928","CVE-2026-48930","CVE-2026-48931","CVE-2026-48933","CVE-2026-48934","CVE-2026-48935","CVE-2026-48937","CVE-2026-6733","CVE-2026-9496","CVE-2026-9679"],"summary":"Security update for nodejs22","details":"This update for nodejs22 fixes the following issues\n\nUpdate to 22.23.0:\n\n- CVE-2026-6733: undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response\n  delivery (bsc#1268479).\n- CVE-2026-9496: pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec`\n  value can lead to DoS (bsc#1266318).\n- CVE-2026-9679: undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding (bsc#1268477).\n- CVE-2026-11525: undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header\n  (bsc#1268481).\n- CVE-2026-12151: undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (bsc#1268482).\n- CVE-2026-21637: synchronous exceptions thrown during certain callbacks bypass the standard TLS error handling paths\n  and can cause a denial of service (bsc#1256576).\n- CVE-2026-21710: uncaught TypeError exception can cause a denial of service (bsc#1260455).\n- CVE-2026-21713: timing side-channel in HMAC verification via memcmp can lead to potential MAC forgery (bsc#1260463).\n- CVE-2026-21714: WINDOW_UPDATE frames on stream 0 can lead to memory leak (bsc#1260480).\n- CVE-2026-21715: permission model bypass in realpathSync.native can allow file existence disclosure (bsc#1260482).\n- CVE-2026-21716: promise-based FileHandle methods can be used to modify file permissions and ownership (bsc#1260462).\n- CVE-2026-21717: crafted request can lead to hash collisions trivially predictable (bsc#1260494).\n- CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853).\n- CVE-2026-40170: ngtcp2: qlog parameters_set stack buffer overflow (bsc#1262274).\n- CVE-2026-42338: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (bsc#1268097).\n- CVE-2026-48615: Proxy credentials leaked in ERR_PROXY_TUNNEL error message (bsc#1268598).\n- CVE-2026-48617: permission model enforcement bypass via `process.report.writeReport()` path misvalidation\n  (bsc#1268554).\n- CVE-2026-48618: Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to\n  resolver and verifier hostname normalization mismatch (bsc#1268593).\n- CVE-2026-48619: Unbounded memory growth in node:http2 clients via attacker-controlled ORIGIN frames (bsc#1268618).\n- CVE-2026-48928: Uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname\n  matching (bsc#1268605).\n- CVE-2026-48930: Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver\n  bindings (bsc#1268606).\n- CVE-2026-48931: HTTP Response Queue Poisoning via TOCTOU Race Condition in http.Agent (bsc#1268611).\n- CVE-2026-48933: Node.js WebCrypto AES Integer Overflow Leads to Remote Process Abort (bsc#1268592).\n- CVE-2026-48934: TLS host identity verification bypass via session reuse with different servername leads to\n  unauthorized connections (bsc#1268608).\n- CVE-2026-48935: Permission Model bypass via FileHandle.utimes() in the promises API (bsc#1268609).\n- CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555).\n","affected":[{"package":{"name":"nodejs22","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/nodejs22&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"22.23.0-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"corepack22":"22.23.0-160000.1.1","nodejs22":"22.23.0-160000.1.1","nodejs22-devel":"22.23.0-160000.1.1","nodejs22-docs":"22.23.0-160000.1.1","npm22":"22.23.0-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21058-1.json"}}],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256576"},{"type":"REPORT","url":"https://bugzilla.suse.com/1259853"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260455"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260462"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260463"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260480"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260482"},{"type":"REPORT","url":"https://bugzilla.suse.com/1260494"},{"type":"REPORT","url":"https://bugzilla.suse.com/1262274"},{"type":"REPORT","url":"https://bugzilla.suse.com/1266318"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268097"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268477"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268479"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268481"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268482"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268554"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268555"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268592"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268593"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268598"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268605"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268606"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268608"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268609"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268611"},{"type":"REPORT","url":"https://bugzilla.suse.com/1268618"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-11525"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-12151"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21637"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21710"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21713"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21714"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21715"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21716"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-21717"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-27135"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-40170"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-42338"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48615"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48617"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48618"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48619"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48928"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48930"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48931"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48933"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48934"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48935"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-48937"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-6733"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9496"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-9679"}]}