-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 22 Sep 2026 19:12:18 +0200 Source: nodejs Binary: libnode-dev libnode115 libnode115-dbgsym nodejs nodejs-dbgsym Architecture: amd64 Version: 20.19.2+dfsg-1+deb13u3 Distribution: trixie-security Urgency: medium Maintainer: all / amd64 / i386 Build Daemon (x86-conova-01) Changed-By: Bastien Roucariès Description: libnode-dev - evented I/O for V8 javascript (development files) libnode115 - evented I/O for V8 javascript - runtime library nodejs - evented I/O for V8 javascript - runtime executable Changes: nodejs (20.19.2+dfsg-1+deb13u3) trixie-security; urgency=medium . * Team upload * Fix CVE-2026-48617: A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48618: A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48619: A malicious HTTP/2 server can send repeated ORIGIN frames with unique origins, causing unbounded growth of the client-side originSet for the lifetime of the session. Cap the set at 128 entries; once full, new origins from ORIGIN frames are silently dropped. * Fix CVE-2026-48928: case-sensitive SNI context matching The regex constructed by server.addContext() lacked the case-insensitive flag, causing uppercase or mixed-case SNI hostnames from ClientHello to miss their intended context and fall back to the default context. This violates RFC 6066 Section 3, which states that DNS hostnames are case-insensitive. In mTLS configurations with per-tenant contexts, this allowed bypassing client certificate authorization by simply uppercasing the SNI hostname. * Fix CVE-2026-48930: A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. * Fix CVE-2026-48931: HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. * Fix CVE-2026-48933: A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. * Fix CVE-2026-48934: A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. * Fix CVE-2026-48935: A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. --allow-fs-read. * Fix CVE-2026-48937: A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. * Fix CVE-2026-56846 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. * Fix CVE-2026-56847: A flaw in Node.js Permission Model enforcement allows trace_events.createTracing().enable() Writes Trace Logs Outside --allow-fs-write. * Fix CVE-2026-56848: A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. * Fix CVE-2026-56850: A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. * Fix CVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations * Fix CVE-2026-58043! A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. * Fix CVE-2026-58040: An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). Checksums-Sha1: 6444d6810ac8fd5ac7333f6b886ae7a5bf68a332 538476 libnode-dev_20.19.2+dfsg-1+deb13u3_amd64.deb b1cb5880e745e349d855038ce9d9bcd02572ef37 1035037820 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_amd64.deb 53166016dbfdc23284f3c39afacf31ca6575f42c 12093268 libnode115_20.19.2+dfsg-1+deb13u3_amd64.deb 248de119f3849b2f237d2d54173300658596ca82 82556 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_amd64.deb 6709d12c15e5ad9bed446d6832fe35e52ec2713f 11225 nodejs_20.19.2+dfsg-1+deb13u3_amd64-buildd.buildinfo 94d3644ab9f405330f1d5c5f2de7af26d2d204c4 354784 nodejs_20.19.2+dfsg-1+deb13u3_amd64.deb Checksums-Sha256: 01becbe539d14549b93abe6b27600dc86501445143a2a4697113db778b9d9f79 538476 libnode-dev_20.19.2+dfsg-1+deb13u3_amd64.deb 49a9e252c8665013a1597f20cf2042277fd1dfaca6bf847388bb7e6a32e1a708 1035037820 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_amd64.deb b459856250d6877cb528526aa3066eff78867fb041a8e8920a867b3f1bb8332f 12093268 libnode115_20.19.2+dfsg-1+deb13u3_amd64.deb 0ba13eeda907e9128c0c07ee24d2e0dbb48f4dda643ce5fd8488238f949fac69 82556 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_amd64.deb fc4db2d058018fbb9ae20e071d4a5253bd3d0ceea4613282a5b14c12527e5124 11225 nodejs_20.19.2+dfsg-1+deb13u3_amd64-buildd.buildinfo 2f30b056911388a3abf27d015eda858bf5b76abfeb7f43b82c3cc35231f1c8bc 354784 nodejs_20.19.2+dfsg-1+deb13u3_amd64.deb Files: 239d9d09881b3c0609d17293779e2006 538476 libdevel optional libnode-dev_20.19.2+dfsg-1+deb13u3_amd64.deb 63399bb46ca980efac167d3f9a7a26c3 1035037820 debug optional libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_amd64.deb 4379eedb30054dbfae47b90c8f21a2f9 12093268 libs optional libnode115_20.19.2+dfsg-1+deb13u3_amd64.deb 7238e6be8805f33bc47fb5f5b978614c 82556 debug optional nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_amd64.deb f0b555e17d586f32ab176bed4e8982ae 11225 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_amd64-buildd.buildinfo ca4cee7b77cc66bea2da2e9d414695cb 354784 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_amd64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7cQ9mRD4+dWjjrb6PkCWRKsh20cFAmqzCygACgkQPkCWRKsh 20drpQ//eiS7jhfzfKfYtK6OpG/9JqX9XAZb551Lr3hcI+HWWfUtyu31RL+lFxUI TUcKMfXHex+mPQLd15uy3gftlTW/n8i2Q4o3d6GWh83i9pCOFs0pa40wQ/jXHz6n 4fmnBrQ8gIqs+tjYtAMKKuYj6YbosCb6SlqB1zPYnSBsZHAhGRyPWNuZZ/CqNTqm fsleukb3T2F9bo9zfRvnFMdk3xgWyrN1/9V0XP88PMoTXq32enhbeykZN0YSFhaz wNIT18kpSrUuhC/63NbKvM6jwsOe6Iamful9SL1RwWdPx0WMUI1vB41eBa558vba KnFQeZtlKyz1zoE8VnHToY5vbcS3xFkB/oo1BRrdpB5PJpipmhxL/nGKYQnT+pTr VvnROLx3YQHSHVU5WbPG0rUpEe4M5W8UCiGNuUul7sLChh8dthMBSrrkR7LYWdGV NmfFR8j8qmupz7Os6NjQ/zSZnDWDeGEdZesPK2mpmfnvYTWjEu1yybQNUJkbTYC6 bZ5tLC9p9S+Fn2xzasf/qLHro0ytlTFsbpw5KlXu5xlcJZ8R2o7qYkasMMJbsqYY ac3k09WZP/WRT6FAjfu4o6KXOYjTmapOywz7cO5yb2qRfwapTITUaX7qr9L9nPmo C8WLuYBXXpYbt8AqXaS1hrhUY/02CD8rXjxIfa9x3pL/6ekulRE= =s2Uj -----END PGP SIGNATURE-----