Thank you for your contribution to Debian.


Accepted:

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 22 Sep 2026 19:12:18 +0200
Source: nodejs
Architecture: source
Version: 20.19.2+dfsg-1+deb13u3
Distribution: trixie-security
Urgency: medium
Maintainer: Debian Javascript Maintainers 
<[email protected]>
Changed-By: Bastien Roucariès <[email protected]>
Changes:
 nodejs (20.19.2+dfsg-1+deb13u3) trixie-security; urgency=medium
 .
   * Team upload
   * Fix CVE-2026-48617:
     A flaw in Node.js Permission Model enforcement allows Bypass
     via `process.report.writeReport()` Path Misvalidation.
     This can lead to confidentiality impact or bypass of the
     intended security boundary under affected configurations.
   * Fix CVE-2026-48618:
     A flaw in Node.js TLS hostname handling can cause Node.js unicode
     dot separator handling can lead to tls wildcard-depth
     authentication bypass due to resolver and verifier hostname
     normalization mismat. This can lead to confidentiality impact
     or bypass of the intended security boundary under
     affected configurations.
   * Fix CVE-2026-48619:
     A malicious HTTP/2 server can send repeated ORIGIN frames with unique
     origins, causing unbounded growth of the client-side originSet for the
     lifetime of the session. Cap the set at 128 entries; once full, new
     origins from ORIGIN frames are silently dropped.
   * Fix CVE-2026-48928: case-sensitive SNI context matching
     The regex constructed by server.addContext() lacked the case-insensitive
     flag, causing uppercase or mixed-case SNI hostnames from ClientHello to
     miss their intended context and fall back to the default context. This
     violates RFC 6066 Section 3, which states that DNS hostnames are
     case-insensitive. In mTLS configurations with per-tenant contexts, this
     allowed bypassing client certificate authorization by simply
     uppercasing the SNI hostname.
   * Fix CVE-2026-48930:
     A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames
     can lead to silent authority rebinding due to c-string truncation
     in resolver bindings.
   * Fix CVE-2026-48931:
     HTTP Agent can cause a client to accept as valid a response
     that is send before the client has sent the request.
   * Fix CVE-2026-48933:
     A flaw in Node.js WebCrypto implementation can crash the process
     if the input of `subtle.encrypt()` is a multiple of 2GiB.
   * Fix CVE-2026-48934:
     A flaw in Node.js TLS host verification can cause an attacker
     to bypass certification validation.
   * Fix CVE-2026-48935:
     A flaw in Node.js Permission API can cause a file metadata
     to be modified even on a path that was set as read-only
     with e.g. --allow-fs-read.
   * Fix CVE-2026-48937:
     A flaw in Node.js HTTP/2 server API can cause servers
     to keep accepting data even after sending a `GOAWAY` frame.
   * Fix CVE-2026-56846
     A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained
     header blocks evade maxSessionMemory
     and enable remote memory exhaustion.
   * Fix CVE-2026-56847:
     A flaw in Node.js Permission Model enforcement allows
     trace_events.createTracing().enable() Writes Trace Logs
     Outside --allow-fs-write.
   * Fix CVE-2026-56848:
     A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()`
     to be called re-entrantly while `nghttp2_session_mem_recv()` is executing,
     resulting in a heap-use-after-free.
   * Fix CVE-2026-56850:
     A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array
     key collisions, allowing mutual TLS (mTLS) client identities to be
     reused across requests configured with different client certificates.
   * Fix CVE-2026-58039:
     A flaw in Node.js Permission Model enforcement allows process.report writes
     (and overwrites) files outside --allow-fs-write paths.
     This can lead to confidentiality impact or bypass of the intended
     security boundary under affected configurations
   * Fix CVE-2026-58043!
     A flaw in Node.js Permission Model enforcement can over-grant
     filesystem access across radix-tree prefix boundaries.
     Under `--permission`, an attacker who is granted access to one
     path can abuse boundary handling to read from or write to paths
     outside the intended filesystem allowlist.
   * Fix CVE-2026-58040:
     An incomplete fix has been identified in Node.js: HTTPS Agent
     TLS session reuse skips hostname verification across identity policies
     (incomplete fix of CVE-2026-48934).
Checksums-Sha1:
 8858ad057cef43de579d33eb7cfd5c08ec62958c 4385 nodejs_20.19.2+dfsg-1+deb13u3.dsc
 36d594cccc87915a298fccaa4f30843f6a7af2ec 274900 
nodejs_20.19.2+dfsg.orig-ada.tar.xz
 c3753ad4a19367bb34d4b34d6f28276b8a139038 303700 
nodejs_20.19.2+dfsg.orig-types-node.tar.xz
 7ed7a340dc165334953d0a57eb4c2600e4d3081a 19886184 
nodejs_20.19.2+dfsg.orig.tar.xz
 5cd00870e637aba93df0c44ac644258e5e45998c 237612 
nodejs_20.19.2+dfsg-1+deb13u3.debian.tar.xz
 78cc70b5917cdd0e224e347a2bbe146b7fea86e2 9712 
nodejs_20.19.2+dfsg-1+deb13u3_source.buildinfo
Checksums-Sha256:
 d70bf116f5f10b7d992ae527cc0a60e95ac7df308c16affb43b3776897220830 4385 
nodejs_20.19.2+dfsg-1+deb13u3.dsc
 26deff017c505b316f2498aaf293c896f4ab92b5349b367cf21fe14fa2cbd1e1 274900 
nodejs_20.19.2+dfsg.orig-ada.tar.xz
 cacb4b47fe0ad9250294545a33e5097c50b0a86f7bd1862cd73f99385f69a174 303700 
nodejs_20.19.2+dfsg.orig-types-node.tar.xz
 5e5559381ad031d245a8efa403458abbb73755f74c3e6380f185a4dd342b7949 19886184 
nodejs_20.19.2+dfsg.orig.tar.xz
 ce0e2e1a48255cb505fa57665b439b9601042a8b33e196ac1118f8265c14df3c 237612 
nodejs_20.19.2+dfsg-1+deb13u3.debian.tar.xz
 c02ab724c5cac466c823f00cd4b2d5e6e00a360c9575fde701f963b7cb688d58 9712 
nodejs_20.19.2+dfsg-1+deb13u3_source.buildinfo
Files:
 54987f3e1a899ab508f6d30a58e8497a 4385 javascript optional 
nodejs_20.19.2+dfsg-1+deb13u3.dsc
 fd9ff3be8b8b43905dd24c5af24aab16 274900 javascript optional 
nodejs_20.19.2+dfsg.orig-ada.tar.xz
 a1bc896abb59372639fc59c82e40a517 303700 javascript optional 
nodejs_20.19.2+dfsg.orig-types-node.tar.xz
 8b4b3615193af364ccde831591e81402 19886184 javascript optional 
nodejs_20.19.2+dfsg.orig.tar.xz
 dc179f314c7888b8420d1badf41ed3cc 237612 javascript optional 
nodejs_20.19.2+dfsg-1+deb13u3.debian.tar.xz
 b93a6f021c44f4d8227099f6978559e9 9712 javascript optional 
nodejs_20.19.2+dfsg-1+deb13u3_source.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmqy8uEACgkQADoaLapB
CF9t0w/9HfdG50IEhOxFGhAUyzTHo3aN7t0Mn84XDkeiuz87SOkzHpT/ZuWQkS11
/K9WjSltsFLo52m4t2gbIRc4UhTrD4zdqasaD8dukST3anGKIyAQyV4Ufjjb0NsW
AcQaBaLiUFC65mYqOyKL6OAVkLzNpjdYuAoLtWXGuRQ5JXjgFizUT+ZNH3olMl5f
wNRqzNWqZ5xXj+VIfmDOQLVsgsLCxpobUIcIqzS/Z0O4suPgyn1zGQ0Vc9PNpMA3
+oR1bOPDkFGX7PhiYfT1FdOrQVNUdwoPtec1Rd2UDcJb75/+Y12PKyC8Xv3tGTE+
loo/DsqVrOxxJFpWDL+/Co72yw6UhwbFwnrS+6UvgaT9Z2Sfcd0b0tg9iDvnhVJf
jdtddkxNT5do12puavoYf2Vfc+h97aALSVztJYeTQSzWBoSudSlsmhRgim5Bn/Nq
BLVjJef2PyCEmUm7yvcXAqRLgoG2lAQZINEV1paczlC2KweVPPz2DTAi98cIcaJ0
QSy6F3xiAis73efujeWn6dzuJ3vOPQD++l1fN3Q9y1RBCffy0nbe06n5xF/AN3a/
AGkH0fkgn7K96A71dX/060hgLk0xdc23RAge2+gAFKCHXhDIqusnbtN2gjy3qKvy
kJ1uM3jiAkt5KZadV24dYRKXvhneOcnW2EgnRBfL/iwuwJ5+zNs=
=F1mM
-----END PGP SIGNATURE-----

Attachment: pgprtQy0nAmD6.pgp
Description: PGP signature

-- 
Pkg-javascript-devel mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-javascript-devel

Reply via email to