-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 16 Aug 2026 19:34:06 +0200 Source: nodejs Architecture: source Version: 18.20.4+dfsg-1~deb12u3 Distribution: bookworm-security Urgency: high Maintainer: Debian Javascript Maintainers <pkg-javascript-devel@alioth-lists.debian.net> Changed-By: Bastien Roucariès <rouca@debian.org> Changes: nodejs (18.20.4+dfsg-1~deb12u3) bookworm-security; urgency=high . * Team upload * Fix CVE-2026-48618: A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismatch * Fix CVE-2026-48618: A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48928: case-sensitive SNI context matching The regex constructed by server.addContext() lacked the case-insensitive flag, causing uppercase or mixed-case SNI hostnames from ClientHello to miss their intended context and fall back to the default context. This violates RFC 6066 Section 3, which states that DNS hostnames are case-insensitive. In mTLS configurations with per-tenant contexts, this allowed bypassing client certificate authorization by simply uppercasing the SNI hostname. * Fix CVE-2026-48930: A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. * Fix CVE-2026-48931: HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. * Fix CVE-2026-48933: A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. * Fix CVE-2026-48934: A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. * Fix CVE-2026-56846 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. * Fix CVE-2026-56848: A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. * Fix CVE-2026-56850: A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. * Fix CVE-2026-58042: A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated triggering of this condition can lead to denial of service. * Fix CVE-2026-58040: An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). * Fix FTBFS due to openssl changes Checksums-Sha1: 458bc5b9764c2ba1817e0eaa8d234d02de46b854 4334 nodejs_18.20.4+dfsg-1~deb12u3.dsc 4e580579ef4a73cf6ab060c74433501f292c18d3 272924 nodejs_18.20.4+dfsg.orig-ada.tar.xz 4cad22f4545483163b468271d06f425b15f1dcf0 267236 nodejs_18.20.4+dfsg.orig-types-node.tar.xz a0c8b9acf0982e9010edb24542aa83d55e65fbde 29390728 nodejs_18.20.4+dfsg.orig.tar.xz 337643ec735d6b99713d22198905281bdd8448be 204840 nodejs_18.20.4+dfsg-1~deb12u3.debian.tar.xz 06e20c3c5aecb29d073cf91106a598609136dd00 9901 nodejs_18.20.4+dfsg-1~deb12u3_source.buildinfo Checksums-Sha256: 917ea928fb7ecc17403b0bf846176fb26779cab953530259aa3b95a5aa2349be 4334 nodejs_18.20.4+dfsg-1~deb12u3.dsc b58fd8b7ef61255b66d42b66e32e74ccdde61c4e02facd6b5a566618e32e993e 272924 nodejs_18.20.4+dfsg.orig-ada.tar.xz 5bd8293f0adfb7bc744e3071bdbd184fd02f973931396ba816ff61514ecd62a9 267236 nodejs_18.20.4+dfsg.orig-types-node.tar.xz 6ce58062c71eae37d9c5ac31eeaeff9c2d48561d21c2849179d056c9c1bd9ebc 29390728 nodejs_18.20.4+dfsg.orig.tar.xz 983ceb41c628041699d510d1766b14b6f1486ec1eb22363f3f45862cb7c2525c 204840 nodejs_18.20.4+dfsg-1~deb12u3.debian.tar.xz 4a5cc8fe44eeb4f5593d41d2bb6b6b1305c7aa0d3e7e391896476434cdd5ee51 9901 nodejs_18.20.4+dfsg-1~deb12u3_source.buildinfo Files: 8fa62677156517f50e6515cd1c7781e6 4334 javascript optional nodejs_18.20.4+dfsg-1~deb12u3.dsc 774dbd4a3931a17737b3c27a7a67d587 272924 javascript optional nodejs_18.20.4+dfsg.orig-ada.tar.xz 8cabd2aa436c05f698a17368826a8645 267236 javascript optional nodejs_18.20.4+dfsg.orig-types-node.tar.xz 157a1ca8a7c3ca2465402e0326511581 29390728 javascript optional nodejs_18.20.4+dfsg.orig.tar.xz 0287f1a7b868fcadb58111fcf353d33b 204840 javascript optional nodejs_18.20.4+dfsg-1~deb12u3.debian.tar.xz 3cf4fd6e6edd7896de26132c41fce70f 9901 javascript optional nodejs_18.20.4+dfsg-1~deb12u3_source.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEXQGHuUCiRbrXsPVqADoaLapBCF8FAmq+VVAACgkQADoaLapB CF9XNA/+LT9qu0ehu+Ow7r2qg71gnR9VUkRpYApJuXXMPBLBh2cFW9CpxE6WLcWI 2hhwjmP9Zo5wfxZ15GGqJxgIj0A5XXZSfqJuMNF1X5veQ2+doosobEwG33oTxgK8 fPvVqo/zSS94i+cuUBvQJs826bkmjUMN4VL3/LyLlzlQ4uSl206XHLvqybz0yy84 sIFmnVsgJDFE8KE3lhxwLy7S0DW/3pwcmqEhuM491yP/radDU7l+PJd97UNm1BZ9 D6HETekjILVQQiQuZlHKkl+JvGp3+FTXWPm0tw6erK2DddOolFBkSSS8yQaLVQlY Cfmg7ufVMVxVxhw1iGY4vvBNeA5hZ31sZbwYlZRBpcJdqhk9T8h68KGu7HjRkZoO MGYN/qF2KUg0qeRXJ4UZkPJBlBnzkoHE0bvsK/hvtjgw/36kPgt67Jhg2WI9hu+3 8BWOmljuaFrHs1xs9OsUahJHWI/NYNx50eQpTa4iQi1F91VWEDM9MRDT/eItD9Ij w2uWUXO5mMTw0xVAQO5VkQOYy5visa9pzQGaO/907CJAGL+zDeahLqJuXc2yXftS t8jVUAFKnmL4l5ZSFuYXW3eG5pYB1o31Oii88w0ddYmGcnn3DNIxbHMF6wvsPpqO e7xZ12RKuhzpEjUCHyoCbjRTn/9rL7ghJVOXg9W/lxM38QAir4A= =OiMe -----END PGP SIGNATURE-----