[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:20519-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-07-31T11:19:25.255Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":32,"duplicates":33,"related":34,"reserved_at":9,"published_at":44,"modified_at":45,"state":9,"summary":46,"references_raw":48,"kevs":124,"epss":9,"epss_history":125,"metrics":126,"affected":127},"OPENSUSE-SU-2026:20519-1","Security update for nodejs24\n\nThis update for nodejs24 fixes the following issues:\n\nUpdate to version 24.14.1.\n\nSecurity issues fixed:\n\n- CVE-2026-21717: trivially predictable hash collisions due to flaw in V8's string hashing mechanism allows for\n  performance degradation via a crafted request (bsc#1260494).\n- CVE-2026-21716: incomplete fix for CVE-2024-36137 allows promise-based FileHandle methods to be used to modify file\n  permissions and ownership on already-open file descriptors (bsc#1260462).\n- CVE-2026-21715: flaw in the Permission Model filesystem enforcement allows for file existence disclosure and\n  filesystem path enumeration via `fs.realpathSync.native()` (bsc#1260482).\n- CVE-2026-21714: memory leak in Node.js HTTP/2 server allows for resource exhaustion via `WINDOW_UPDATE` frames sent\n  on stream 0 (bsc#1260480).\n- CVE-2026-21713: timing side-channel due to flaw in Node.js HMAC verification allows for discovery of HMAC values and\n  potential MAC forgery (bsc#1260463).\n- CVE-2026-21712: assertion error caused by flaw in URL processing allows for a process crash via a URL with a\n  malformed IDN (bsc#1260460).\n- CVE-2026-21710: uncaught `TypeError` when handling HTTP requests allows for a process crash via requests with a\n  header named `__proto__` when the application accesses `req.headersDistinct` (bsc#1260455).\n- CVE-2026-21637: flaw in TLS error handling allows for resource exhaustion and crash when `pskCallback` or\n  `ALPNCallback` are in use (bsc#1256576).\n- CVE-2025-59464: memory leak allows for remote denial of service against applications processing TLS client\n  certificates (bsc#1256572).\n\nOther updates and bugfixes:\n\n- Version 24.14.0:\n  * async_hooks: add trackPromises option to createHook()\n  * build,deps: replace cjs-module-lexer with merve\n  * deps: add LIEF as a dependency\n  * events: repurpose events.listenerCount() to accept EventTargets\n  * fs: add ignore option to fs.watch\n  * http: add http.setGlobalProxyFromEnv()\n  * module: allow subpath imports that start with #/\n  * process: preserve AsyncLocalStorage in queueMicrotask only when needed\n  * sea: split sea binary manipulation code\n  * sqlite: enable defensive mode by default\n  * sqlite: add sqlite prepare options args\n  * src: add initial support for ESM in embedder API\n  * stream: add bytes() method to node:stream/consumers\n  * stream: do not pass readable.compose() output via Readable.from()\n  * test: use fixture directories for sea tests\n  * test_runner: add env option to run function\n  * test_runner: support expecting a test-case to fail\n  * util: add convertProcessSignalToExitCode utility\n  * For details, see https://nodejs.org/en/blog/release/v24.14.0\n\n",null,[],[],[],[14,16,18,20,22,24,26,28,30],{"_key":15},"CVE-2025-59464",{"_key":17},"CVE-2026-21637",{"_key":19},"CVE-2026-21710",{"_key":21},"CVE-2026-21712",{"_key":23},"CVE-2026-21713",{"_key":25},"CVE-2026-21714",{"_key":27},"CVE-2026-21715",{"_key":29},"CVE-2026-21716",{"_key":31},"CVE-2026-21717",[],[],[35,36,37,38,39,40,41,42,43],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},"2026-04-13T12:29:51Z","2026-04-22T18:26:56.813188Z",{"cisa_kev":47,"cisa_ransomware":47,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[49,55,59,63,67,71,75,79,83,87,92,96,100,104,108,112,116,120],{"url":50,"sources":51,"tags":53},"https://bugzilla.suse.com/1256572",[52],"osv_opensuse",[54],"REPORT",{"url":56,"sources":57,"tags":58},"https://bugzilla.suse.com/1256576",[52],[54],{"url":60,"sources":61,"tags":62},"https://bugzilla.suse.com/1260455",[52],[54],{"url":64,"sources":65,"tags":66},"https://bugzilla.suse.com/1260460",[52],[54],{"url":68,"sources":69,"tags":70},"https://bugzilla.suse.com/1260462",[52],[54],{"url":72,"sources":73,"tags":74},"https://bugzilla.suse.com/1260463",[52],[54],{"url":76,"sources":77,"tags":78},"https://bugzilla.suse.com/1260480",[52],[54],{"url":80,"sources":81,"tags":82},"https://bugzilla.suse.com/1260482",[52],[54],{"url":84,"sources":85,"tags":86},"https://bugzilla.suse.com/1260494",[52],[54],{"url":88,"sources":89,"tags":90},"https://www.suse.com/security/cve/CVE-2025-59464",[52],[91],"WEB",{"url":93,"sources":94,"tags":95},"https://www.suse.com/security/cve/CVE-2026-21637",[52],[91],{"url":97,"sources":98,"tags":99},"https://www.suse.com/security/cve/CVE-2026-21710",[52],[91],{"url":101,"sources":102,"tags":103},"https://www.suse.com/security/cve/CVE-2026-21712",[52],[91],{"url":105,"sources":106,"tags":107},"https://www.suse.com/security/cve/CVE-2026-21713",[52],[91],{"url":109,"sources":110,"tags":111},"https://www.suse.com/security/cve/CVE-2026-21714",[52],[91],{"url":113,"sources":114,"tags":115},"https://www.suse.com/security/cve/CVE-2026-21715",[52],[91],{"url":117,"sources":118,"tags":119},"https://www.suse.com/security/cve/CVE-2026-21716",[52],[91],{"url":121,"sources":122,"tags":123},"https://www.suse.com/security/cve/CVE-2026-21717",[52],[91],[],[],[],[128],{"ecosystem":129,"name":130,"vendor":131,"product":132,"cpe_part":9,"purl_type":133,"purl_namespace":131,"purl_name":132,"source":9,"versions":134},"openSUSE","nodejs24","opensuse","nodejs24&distro=openSUSE Leap 16.0","rpm",[135],{"version":136,"is_range":137,"range_type":138,"version_start":9,"version_start_type":9,"version_end":139,"version_end_type":140,"fixed_in":9},"lt24_14_1_160000_1_1",true,"ecosystem","24.14.1-160000.1.1","excluding"]