-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 22 Sep 2026 19:12:18 +0200 Source: nodejs Architecture: source Version: 20.19.2+dfsg-1+deb13u3 Distribution: trixie-security Urgency: medium Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@alioth-lists.debian.net> Changed-By: Bastien Roucariès <rouca@debian.org> Changes: nodejs (20.19.2+dfsg-1+deb13u3) trixie-security; urgency=medium . * Team upload * Fix CVE-2026-48617: A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48618: A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48619: A malicious HTTP/2 server can send repeated ORIGIN frames with unique origins, causing unbounded growth of the client-side originSet for the lifetime of the session. Cap the set at 128 entries; once full, new origins from ORIGIN frames are silently dropped. * Fix CVE-2026-48928: case-sensitive SNI context matching The regex constructed by server.addContext() lacked the case-insensitive flag, causing uppercase or mixed-case SNI hostnames from ClientHello to miss their intended context and fall back to the default context. This violates RFC 6066 Section 3, which states that DNS hostnames are case-insensitive. In mTLS configurations with per-tenant contexts, this allowed bypassing client certificate authorization by simply uppercasing the SNI hostname. * Fix CVE-2026-48930: A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. * Fix CVE-2026-48931: HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. * Fix CVE-2026-48933: A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. * Fix CVE-2026-48934: A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. * Fix CVE-2026-48935: A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. --allow-fs-read. * Fix CVE-2026-48937: A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. * Fix CVE-2026-56846 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. * Fix CVE-2026-56847: A flaw in Node.js Permission Model enforcement allows trace_events.createTracing().enable() Writes Trace Logs Outside --allow-fs-write. * Fix CVE-2026-56848: A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. * Fix CVE-2026-56850: A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. * Fix CVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations * Fix CVE-2026-58043! A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. * Fix CVE-2026-58040: An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). Checksums-Sha1: 8858ad057cef43de579d33eb7cfd5c08ec62958c 4385 nodejs_20.19.2+dfsg-1+deb13u3.dsc 36d594cccc87915a298fccaa4f30843f6a7af2ec 274900 nodejs_20.19.2+dfsg.orig-ada.tar.xz c3753ad4a19367bb34d4b34d6f28276b8a139038 303700 nodejs_20.19.2+dfsg.orig-types-node.tar.xz 7ed7a340dc165334953d0a57eb4c2600e4d3081a 19886184 nodejs_20.19.2+dfsg.orig.tar.xz 5cd00870e637aba93df0c44ac644258e5e45998c 237612 nodejs_20.19.2+dfsg-1+deb13u3.debian.tar.xz 78cc70b5917cdd0e224e347a2bbe146b7fea86e2 9712 nodejs_20.19.2+dfsg-1+deb13u3_source.buildinfo Checksums-Sha256: d70bf116f5f10b7d992ae527cc0a60e95ac7df308c16affb43b3776897220830 4385 nodejs_20.19.2+dfsg-1+deb13u3.dsc 26deff017c505b316f2498aaf293c896f4ab92b5349b367cf21fe14fa2cbd1e1 274900 nodejs_20.19.2+dfsg.orig-ada.tar.xz cacb4b47fe0ad9250294545a33e5097c50b0a86f7bd1862cd73f99385f69a174 303700 nodejs_20.19.2+dfsg.orig-types-node.tar.xz 5e5559381ad031d245a8efa403458abbb73755f74c3e6380f185a4dd342b7949 19886184 nodejs_20.19.2+dfsg.orig.tar.xz ce0e2e1a48255cb505fa57665b439b9601042a8b33e196ac1118f8265c14df3c 237612 nodejs_20.19.2+dfsg-1+deb13u3.debian.tar.xz c02ab724c5cac466c823f00cd4b2d5e6e00a360c9575fde701f963b7cb688d58 9712 nodejs_20.19.2+dfsg-1+deb13u3_source.buildinfo Files: 54987f3e1a899ab508f6d30a58e8497a 4385 javascript optional nodejs_20.19.2+dfsg-1+deb13u3.dsc fd9ff3be8b8b43905dd24c5af24aab16 274900 javascript optional nodejs_20.19.2+dfsg.orig-ada.tar.xz a1bc896abb59372639fc59c82e40a517 303700 javascript optional nodejs_20.19.2+dfsg.orig-types-node.tar.xz 8b4b3615193af364ccde831591e81402 19886184 javascript optional nodejs_20.19.2+dfsg.orig.tar.xz dc179f314c7888b8420d1badf41ed3cc 237612 javascript optional nodejs_20.19.2+dfsg-1+deb13u3.debian.tar.xz b93a6f021c44f4d8227099f6978559e9 9712 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmqy8uEACgkQADoaLapB CF9t0w/9HfdG50IEhOxFGhAUyzTHo3aN7t0Mn84XDkeiuz87SOkzHpT/ZuWQkS11 /K9WjSltsFLo52m4t2gbIRc4UhTrD4zdqasaD8dukST3anGKIyAQyV4Ufjjb0NsW AcQaBaLiUFC65mYqOyKL6OAVkLzNpjdYuAoLtWXGuRQ5JXjgFizUT+ZNH3olMl5f wNRqzNWqZ5xXj+VIfmDOQLVsgsLCxpobUIcIqzS/Z0O4suPgyn1zGQ0Vc9PNpMA3 +oR1bOPDkFGX7PhiYfT1FdOrQVNUdwoPtec1Rd2UDcJb75/+Y12PKyC8Xv3tGTE+ loo/DsqVrOxxJFpWDL+/Co72yw6UhwbFwnrS+6UvgaT9Z2Sfcd0b0tg9iDvnhVJf jdtddkxNT5do12puavoYf2Vfc+h97aALSVztJYeTQSzWBoSudSlsmhRgim5Bn/Nq BLVjJef2PyCEmUm7yvcXAqRLgoG2lAQZINEV1paczlC2KweVPPz2DTAi98cIcaJ0 QSy6F3xiAis73efujeWn6dzuJ3vOPQD++l1fN3Q9y1RBCffy0nbe06n5xF/AN3a/ AGkH0fkgn7K96A71dX/060hgLk0xdc23RAge2+gAFKCHXhDIqusnbtN2gjy3qKvy kJ1uM3jiAkt5KZadV24dYRKXvhneOcnW2EgnRBfL/iwuwJ5+zNs= =F1mM -----END PGP SIGNATURE-----