-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 22 Sep 2026 19:12:18 +0200 Source: nodejs Binary: libnode-dev libnode115 libnode115-dbgsym nodejs nodejs-dbgsym Architecture: s390x Version: 20.19.2+dfsg-1+deb13u3 Distribution: trixie-security Urgency: medium Maintainer: s390x Build Daemon (ziehrer) Changed-By: Bastien Roucariès Description: libnode-dev - evented I/O for V8 javascript (development files) libnode115 - evented I/O for V8 javascript - runtime library nodejs - evented I/O for V8 javascript - runtime executable Changes: nodejs (20.19.2+dfsg-1+deb13u3) trixie-security; urgency=medium . * Team upload * Fix CVE-2026-48617: A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48618: A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48619: A malicious HTTP/2 server can send repeated ORIGIN frames with unique origins, causing unbounded growth of the client-side originSet for the lifetime of the session. Cap the set at 128 entries; once full, new origins from ORIGIN frames are silently dropped. * Fix CVE-2026-48928: case-sensitive SNI context matching The regex constructed by server.addContext() lacked the case-insensitive flag, causing uppercase or mixed-case SNI hostnames from ClientHello to miss their intended context and fall back to the default context. This violates RFC 6066 Section 3, which states that DNS hostnames are case-insensitive. In mTLS configurations with per-tenant contexts, this allowed bypassing client certificate authorization by simply uppercasing the SNI hostname. * Fix CVE-2026-48930: A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. * Fix CVE-2026-48931: HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. * Fix CVE-2026-48933: A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. * Fix CVE-2026-48934: A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. * Fix CVE-2026-48935: A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. --allow-fs-read. * Fix CVE-2026-48937: A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. * Fix CVE-2026-56846 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. * Fix CVE-2026-56847: A flaw in Node.js Permission Model enforcement allows trace_events.createTracing().enable() Writes Trace Logs Outside --allow-fs-write. * Fix CVE-2026-56848: A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. * Fix CVE-2026-56850: A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. * Fix CVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations * Fix CVE-2026-58043! A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. * Fix CVE-2026-58040: An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). Checksums-Sha1: 1da9d760735bcffc80c70afb7f8f6216c468c0d9 538536 libnode-dev_20.19.2+dfsg-1+deb13u3_s390x.deb 6d98484df1e6aed3f5d7386a7df1f888aef8aaa1 1078168848 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_s390x.deb 25611bb02b459a3d0f69ceb81fc1148f93aaf13e 12211888 libnode115_20.19.2+dfsg-1+deb13u3_s390x.deb 2b31a088547e5effbddfc3446b3e20acd17eb8a4 82552 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_s390x.deb 916ff2d557b3088f3d943192211579e9f5a9ef29 11087 nodejs_20.19.2+dfsg-1+deb13u3_s390x-buildd.buildinfo 217405e96bf5f7b08bbbaf27633b6b9d31f06e82 354668 nodejs_20.19.2+dfsg-1+deb13u3_s390x.deb Checksums-Sha256: 0fdc4434cda455163a37ff50005e5f9dfd238d2a02a9d493cfb0a954b2e80b03 538536 libnode-dev_20.19.2+dfsg-1+deb13u3_s390x.deb 26ebb68f3f910f308e1264364a8c626a3c03a7602881a1d4ca15d9f9a9961830 1078168848 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_s390x.deb baa14c637fb38f5b0106383e9ece43b99425d756e55ff7dc9fddcc0be47ab319 12211888 libnode115_20.19.2+dfsg-1+deb13u3_s390x.deb d0645c5a8bbaff881288005c0a3b8ecfc5f9655297fb0597b8c9d7588b8dffed 82552 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_s390x.deb e79441e38a54ff928c98a4241ce2c1d4b34e21e7ac20ea26ef19707dd4bbd79f 11087 nodejs_20.19.2+dfsg-1+deb13u3_s390x-buildd.buildinfo 9f1a60e07de2b52c1cbe870e03c9ac5ea4b4892f2a91b31398e57f79b7598371 354668 nodejs_20.19.2+dfsg-1+deb13u3_s390x.deb Files: 1687e274ba4bd39de1fcf099df7ffb9b 538536 libdevel optional libnode-dev_20.19.2+dfsg-1+deb13u3_s390x.deb a6e8f831ff9e53f415cd3e1de1eb0b6d 1078168848 debug optional libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_s390x.deb 377421a7d6cfe2ae0f5735f97724c010 12211888 libs optional libnode115_20.19.2+dfsg-1+deb13u3_s390x.deb 0a1840400b3485dbbe6e3eb9b828c589 82552 debug optional nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_s390x.deb ec0fa8ef7de0b68cf587af6556804cd6 11087 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_s390x-buildd.buildinfo c3d37f3928289b280aa31d020c90e3a0 354668 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_s390x.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEl0BM/nR+Oj597wRWMWUFebkHnoQFAmqzCaUACgkQMWUFebkH noR7vA//UZDfMrNM/Ai7d17oTmDF/CSFc3Uwz6hfltDXq85/X1IsslhAgFjQIapf aEYDvQOEb4wnWhHS/bB74Hr/IX2ZPLufuDKnodh+JeyYEn58E+DDFW1b99PKPGMt AYcds5+AtdUImUHvVy4owtW7rU28Ww2mOzqCTXfT87PCGz67BXxinUWOY2XacxIi o5oNBcbNqrOvN8AuwRDE/McdbYmjCNgqAjWsRxzyOUhcKpr1VLJ4BEBXqKOGW3z+ q/nNlIR8fOHDyBaq9Xg+IsIolCnRyzOtD96kAhbMEwhTlTLyrZdoc571cQnsYPl4 tbUIzP06PVl+l8KDYx0u4Lahv0+Kr5pG+atYxrDV+1sH/vOP49/bBVAEJeHfTymG daL29dBgQpALPFr5V14glKx9JmS5nniVwWOjUl8AJOmS86UrKm05tEHjRuWRUfA+ 1i5YuqGfd7zs7tpSlKEf0fdPpxoGs4zWYfgwCMMsecPfWf9HIChRaoaDBImLxjbm XDXL/mgBJ4ZJtQLLgqmsG+Lwg3WLC3W4Bbi3pnC7kKEqJtpjSGNo1fBi2mYrs4kE S14jFc6UbQWOVrHcdVdOTWMazMAqdnxtrtW/5zGnxv+xCl7hM25H4jQR1DOChMUs DO+OrDnd4wgpkP6osCPe4jPK3eLsEWvcE9rqRD3x5KcZXEHa7Ow= =p7Sj -----END PGP SIGNATURE-----