[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21058-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-07-31T11:19:25.255Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":66,"duplicates":67,"related":68,"reserved_at":9,"published_at":95,"modified_at":96,"state":9,"summary":97,"references_raw":99,"kevs":311,"epss":9,"epss_history":312,"metrics":313,"affected":314},"OPENSUSE-SU-2026:21058-1","Security update for nodejs22\n\nThis update for nodejs22 fixes the following issues\n\nUpdate to 22.23.0:\n\n- CVE-2026-6733: undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response\n  delivery (bsc#1268479).\n- CVE-2026-9496: pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec`\n  value can lead to DoS (bsc#1266318).\n- CVE-2026-9679: undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding (bsc#1268477).\n- CVE-2026-11525: undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header\n  (bsc#1268481).\n- CVE-2026-12151: undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (bsc#1268482).\n- CVE-2026-21637: synchronous exceptions thrown during certain callbacks bypass the standard TLS error handling paths\n  and can cause a denial of service (bsc#1256576).\n- CVE-2026-21710: uncaught TypeError exception can cause a denial of service (bsc#1260455).\n- CVE-2026-21713: timing side-channel in HMAC verification via memcmp can lead to potential MAC forgery (bsc#1260463).\n- CVE-2026-21714: WINDOW_UPDATE frames on stream 0 can lead to memory leak (bsc#1260480).\n- CVE-2026-21715: permission model bypass in realpathSync.native can allow file existence disclosure (bsc#1260482).\n- CVE-2026-21716: promise-based FileHandle methods can be used to modify file permissions and ownership (bsc#1260462).\n- CVE-2026-21717: crafted request can lead to hash collisions trivially predictable (bsc#1260494).\n- CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853).\n- CVE-2026-40170: ngtcp2: qlog parameters_set stack buffer overflow (bsc#1262274).\n- CVE-2026-42338: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (bsc#1268097).\n- CVE-2026-48615: Proxy credentials leaked in ERR_PROXY_TUNNEL error message (bsc#1268598).\n- CVE-2026-48617: permission model enforcement bypass via `process.report.writeReport()` path misvalidation\n  (bsc#1268554).\n- CVE-2026-48618: Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to\n  resolver and verifier hostname normalization mismatch (bsc#1268593).\n- CVE-2026-48619: Unbounded memory growth in node:http2 clients via attacker-controlled ORIGIN frames (bsc#1268618).\n- CVE-2026-48928: Uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname\n  matching (bsc#1268605).\n- CVE-2026-48930: Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver\n  bindings (bsc#1268606).\n- CVE-2026-48931: HTTP Response Queue Poisoning via TOCTOU Race Condition in http.Agent (bsc#1268611).\n- CVE-2026-48933: Node.js WebCrypto AES Integer Overflow Leads to Remote Process Abort (bsc#1268592).\n- CVE-2026-48934: TLS host identity verification bypass via session reuse with different servername leads to\n  unauthorized connections (bsc#1268608).\n- CVE-2026-48935: Permission Model bypass via FileHandle.utimes() in the promises API (bsc#1268609).\n- CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555).\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64],{"_key":15},"CVE-2026-11525",{"_key":17},"CVE-2026-12151",{"_key":19},"CVE-2026-21637",{"_key":21},"CVE-2026-21710",{"_key":23},"CVE-2026-21713",{"_key":25},"CVE-2026-21714",{"_key":27},"CVE-2026-21715",{"_key":29},"CVE-2026-21716",{"_key":31},"CVE-2026-21717",{"_key":33},"CVE-2026-27135",{"_key":35},"CVE-2026-40170",{"_key":37},"CVE-2026-42338",{"_key":39},"CVE-2026-48615",{"_key":41},"CVE-2026-48617",{"_key":43},"CVE-2026-48618",{"_key":45},"CVE-2026-48619",{"_key":47},"CVE-2026-48928",{"_key":49},"CVE-2026-48930",{"_key":51},"CVE-2026-48931",{"_key":53},"CVE-2026-48933",{"_key":55},"CVE-2026-48934",{"_key":57},"CVE-2026-48935",{"_key":59},"CVE-2026-48937",{"_key":61},"CVE-2026-6733",{"_key":63},"CVE-2026-9496",{"_key":65},"CVE-2026-9679",[],[],[69,70,71,72,73,74,75,76,77,78,79,80,81,82,83,84,85,86,87,88,89,90,91,92,93,94],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":55},{"_key":57},{"_key":59},{"_key":61},{"_key":63},{"_key":65},"2026-06-25T13:50:58Z","2026-06-30T18:24:37.973780169Z",{"cisa_kev":98,"cisa_ransomware":98,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[100,106,110,114,118,122,126,130,134,138,142,146,150,154,158,162,166,170,174,178,182,186,190,194,198,202,206,211,215,219,223,227,231,235,239,243,247,251,255,259,263,267,271,275,279,283,287,291,295,299,303,307],{"url":101,"sources":102,"tags":104},"https://bugzilla.suse.com/1256576",[103],"osv_opensuse",[105],"REPORT",{"url":107,"sources":108,"tags":109},"https://bugzilla.suse.com/1259853",[103],[105],{"url":111,"sources":112,"tags":113},"https://bugzilla.suse.com/1260455",[103],[105],{"url":115,"sources":116,"tags":117},"https://bugzilla.suse.com/1260462",[103],[105],{"url":119,"sources":120,"tags":121},"https://bugzilla.suse.com/1260463",[103],[105],{"url":123,"sources":124,"tags":125},"https://bugzilla.suse.com/1260480",[103],[105],{"url":127,"sources":128,"tags":129},"https://bugzilla.suse.com/1260482",[103],[105],{"url":131,"sources":132,"tags":133},"https://bugzilla.suse.com/1260494",[103],[105],{"url":135,"sources":136,"tags":137},"https://bugzilla.suse.com/1262274",[103],[105],{"url":139,"sources":140,"tags":141},"https://bugzilla.suse.com/1266318",[103],[105],{"url":143,"sources":144,"tags":145},"https://bugzilla.suse.com/1268097",[103],[105],{"url":147,"sources":148,"tags":149},"https://bugzilla.suse.com/1268477",[103],[105],{"url":151,"sources":152,"tags":153},"https://bugzilla.suse.com/1268479",[103],[105],{"url":155,"sources":156,"tags":157},"https://bugzilla.suse.com/1268481",[103],[105],{"url":159,"sources":160,"tags":161},"https://bugzilla.suse.com/1268482",[103],[105],{"url":163,"sources":164,"tags":165},"https://bugzilla.suse.com/1268554",[103],[105],{"url":167,"sources":168,"tags":169},"https://bugzilla.suse.com/1268555",[103],[105],{"url":171,"sources":172,"tags":173},"https://bugzilla.suse.com/1268592",[103],[105],{"url":175,"sources":176,"tags":177},"https://bugzilla.suse.com/1268593",[103],[105],{"url":179,"sources":180,"tags":181},"https://bugzilla.suse.com/1268598",[103],[105],{"url":183,"sources":184,"tags":185},"https://bugzilla.suse.com/1268605",[103],[105],{"url":187,"sources":188,"tags":189},"https://bugzilla.suse.com/1268606",[103],[105],{"url":191,"sources":192,"tags":193},"https://bugzilla.suse.com/1268608",[103],[105],{"url":195,"sources":196,"tags":197},"https://bugzilla.suse.com/1268609",[103],[105],{"url":199,"sources":200,"tags":201},"https://bugzilla.suse.com/1268611",[103],[105],{"url":203,"sources":204,"tags":205},"https://bugzilla.suse.com/1268618",[103],[105],{"url":207,"sources":208,"tags":209},"https://www.suse.com/security/cve/CVE-2026-11525",[103],[210],"WEB",{"url":212,"sources":213,"tags":214},"https://www.suse.com/security/cve/CVE-2026-12151",[103],[210],{"url":216,"sources":217,"tags":218},"https://www.suse.com/security/cve/CVE-2026-21637",[103],[210],{"url":220,"sources":221,"tags":222},"https://www.suse.com/security/cve/CVE-2026-21710",[103],[210],{"url":224,"sources":225,"tags":226},"https://www.suse.com/security/cve/CVE-2026-21713",[103],[210],{"url":228,"sources":229,"tags":230},"https://www.suse.com/security/cve/CVE-2026-21714",[103],[210],{"url":232,"sources":233,"tags":234},"https://www.suse.com/security/cve/CVE-2026-21715",[103],[210],{"url":236,"sources":237,"tags":238},"https://www.suse.com/security/cve/CVE-2026-21716",[103],[210],{"url":240,"sources":241,"tags":242},"https://www.suse.com/security/cve/CVE-2026-21717",[103],[210],{"url":244,"sources":245,"tags":246},"https://www.suse.com/security/cve/CVE-2026-27135",[103],[210],{"url":248,"sources":249,"tags":250},"https://www.suse.com/security/cve/CVE-2026-40170",[103],[210],{"url":252,"sources":253,"tags":254},"https://www.suse.com/security/cve/CVE-2026-42338",[103],[210],{"url":256,"sources":257,"tags":258},"https://www.suse.com/security/cve/CVE-2026-48615",[103],[210],{"url":260,"sources":261,"tags":262},"https://www.suse.com/security/cve/CVE-2026-48617",[103],[210],{"url":264,"sources":265,"tags":266},"https://www.suse.com/security/cve/CVE-2026-48618",[103],[210],{"url":268,"sources":269,"tags":270},"https://www.suse.com/security/cve/CVE-2026-48619",[103],[210],{"url":272,"sources":273,"tags":274},"https://www.suse.com/security/cve/CVE-2026-48928",[103],[210],{"url":276,"sources":277,"tags":278},"https://www.suse.com/security/cve/CVE-2026-48930",[103],[210],{"url":280,"sources":281,"tags":282},"https://www.suse.com/security/cve/CVE-2026-48931",[103],[210],{"url":284,"sources":285,"tags":286},"https://www.suse.com/security/cve/CVE-2026-48933",[103],[210],{"url":288,"sources":289,"tags":290},"https://www.suse.com/security/cve/CVE-2026-48934",[103],[210],{"url":292,"sources":293,"tags":294},"https://www.suse.com/security/cve/CVE-2026-48935",[103],[210],{"url":296,"sources":297,"tags":298},"https://www.suse.com/security/cve/CVE-2026-48937",[103],[210],{"url":300,"sources":301,"tags":302},"https://www.suse.com/security/cve/CVE-2026-6733",[103],[210],{"url":304,"sources":305,"tags":306},"https://www.suse.com/security/cve/CVE-2026-9496",[103],[210],{"url":308,"sources":309,"tags":310},"https://www.suse.com/security/cve/CVE-2026-9679",[103],[210],[],[],[],[315],{"ecosystem":316,"name":317,"vendor":318,"product":319,"cpe_part":9,"purl_type":320,"purl_namespace":318,"purl_name":319,"source":9,"versions":321},"openSUSE","nodejs22","opensuse","nodejs22&distro=openSUSE Leap 16.0","rpm",[322],{"version":323,"is_range":324,"range_type":325,"version_start":9,"version_start_type":9,"version_end":326,"version_end_type":327,"fixed_in":9},"lt22_23_0_160000_1_1",true,"ecosystem","22.23.0-160000.1.1","excluding"]