[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21236-1":6},{"stargazers_count":4,"fetched_at":5},7,"2026-07-31T17:19:26.604Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":56,"duplicates":57,"related":58,"reserved_at":9,"published_at":80,"modified_at":81,"state":9,"summary":82,"references_raw":84,"kevs":260,"epss":9,"epss_history":261,"metrics":262,"affected":263},"OPENSUSE-SU-2026:21236-1","Security update for nodejs24\n\nThis update for nodejs24 fixes the following issues\n\nUpdate to version 24.18.0 (bsc#1269825).\n\nSecurity issues fixed:\n\n- CVE-2026-2581: undici: denial of service due to uncontrolled resource consumption (bsc#1268480).\n- CVE-2026-6733: undici: response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery\n  (bsc#1268479).\n- CVE-2026-9496: pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec`\n  value can lead to DoS (bsc#1266318).\n- CVE-2026-9678: undici: information disclosure due to improper `cache-control` header parsing (bsc#1268478).\n- CVE-2026-9679: undici: HTTP header injection via `Set-Cookie` percent-decoding (bsc#1268477).\n- CVE-2026-11525: undici: weakening of cookie `SameSite` policy due to incorrect parsing of `Set-Cookie` header\n  (bsc#1268481).\n- CVE-2026-12151: undici: denial of service due to unbounded memory growth via WebSocket frames (bsc#1268482).\n- CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853).\n- CVE-2026-40170: ngtcp2: qlog `parameters_set` stack buffer overflow (bsc#1262274).\n- CVE-2026-42338: ip-address: cross-site scripting due to improper HTML escaping of untrusted input (bsc#1268097).\n- CVE-2026-48615: proxy credentials leaked in `ERR_PROXY_TUNNEL` error message (bsc#1268598).\n- CVE-2026-48617: permission model enforcement bypass via `process.report.writeReport()` path misvalidation\n  (bsc#1268554).\n- CVE-2026-48618: unicode dot separator handling can lead to TLS wildcard-depth authentication bypass due to\n  resolver and verifier hostname normalization mismatch (bsc#1268593).\n- CVE-2026-48619: unbounded memory growth in `node:http2` clients via attacker-controlled `ORIGIN` frames (bsc#1268618).\n- CVE-2026-48928: uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive\n  hostname matching (bsc#1268605).\n- CVE-2026-48930: `embedded-nul` hostnames can lead to silent authority rebinding due to `c-string` truncation in\n  resolver bindings (bsc#1268606).\n- CVE-2026-48931: HTTP response queue poisoning via TOCTOU race condition in `http.Agent` (bsc#1268611).\n- CVE-2026-48933: WebCrypto AES integer overflow leads to remote process abort (bsc#1268592).\n- CVE-2026-48934: TLS host identity verification bypass via session reuse with different `servername` leads to\n  unauthorized connections (bsc#1268608).\n- CVE-2026-48935: permission model bypass via `FileHandle.utimes()` in the `promises` API (bsc#1268609).\n- CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555).\n\nOther updates and bugfixes:\n- Version 24.18.0:\n  - doc: update `blockList` stability status to release candidate\n  - fs: support caller-supplied `readFile()` buffers\n  - http: close pre-request sockets in `closeIdleConnections`\n  - loader: implement package maps\n  - net: support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive`\n  - tls: add `certificateCompression` option\n  - vfs: dispatch `node:fs/promises` to mounted VFS instances\n  - vfs: add minimal `node:vfs` subsystem\n- For changes in older versions, see https://github.com/nodejs/node/releases.\n- Remove `update-alternatives` from scriptlets if not available.\n- Explicitly `BuildRequire` `update-alternatives` and mark it as being used in post/postun.\n- Add `-fno-lifetime-dse` to `CXXFLAGS` to avoid parallel/test-snapshot-reproducible testsuite failure with GCC 16.\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54],{"_key":15},"CVE-2026-11525",{"_key":17},"CVE-2026-12151",{"_key":19},"CVE-2026-2581",{"_key":21},"CVE-2026-27135",{"_key":23},"CVE-2026-40170",{"_key":25},"CVE-2026-42338",{"_key":27},"CVE-2026-48615",{"_key":29},"CVE-2026-48617",{"_key":31},"CVE-2026-48618",{"_key":33},"CVE-2026-48619",{"_key":35},"CVE-2026-48928",{"_key":37},"CVE-2026-48930",{"_key":39},"CVE-2026-48931",{"_key":41},"CVE-2026-48933",{"_key":43},"CVE-2026-48934",{"_key":45},"CVE-2026-48935",{"_key":47},"CVE-2026-48937",{"_key":49},"CVE-2026-6733",{"_key":51},"CVE-2026-9496",{"_key":53},"CVE-2026-9678",{"_key":55},"CVE-2026-9679",[],[],[59,60,61,62,63,64,65,66,67,68,69,70,71,72,73,74,75,76,77,78,79],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":55},"2026-07-06T20:22:33Z","2026-07-09T10:00:10.896109389Z",{"cisa_kev":83,"cisa_ransomware":83,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[85,91,95,99,103,107,111,115,119,123,127,131,135,139,143,147,151,155,159,163,167,171,175,180,184,188,192,196,200,204,208,212,216,220,224,228,232,236,240,244,248,252,256],{"url":86,"sources":87,"tags":89},"https://bugzilla.suse.com/1259853",[88],"osv_opensuse",[90],"REPORT",{"url":92,"sources":93,"tags":94},"https://bugzilla.suse.com/1262274",[88],[90],{"url":96,"sources":97,"tags":98},"https://bugzilla.suse.com/1266318",[88],[90],{"url":100,"sources":101,"tags":102},"https://bugzilla.suse.com/1268097",[88],[90],{"url":104,"sources":105,"tags":106},"https://bugzilla.suse.com/1268477",[88],[90],{"url":108,"sources":109,"tags":110},"https://bugzilla.suse.com/1268478",[88],[90],{"url":112,"sources":113,"tags":114},"https://bugzilla.suse.com/1268479",[88],[90],{"url":116,"sources":117,"tags":118},"https://bugzilla.suse.com/1268480",[88],[90],{"url":120,"sources":121,"tags":122},"https://bugzilla.suse.com/1268481",[88],[90],{"url":124,"sources":125,"tags":126},"https://bugzilla.suse.com/1268482",[88],[90],{"url":128,"sources":129,"tags":130},"https://bugzilla.suse.com/1268554",[88],[90],{"url":132,"sources":133,"tags":134},"https://bugzilla.suse.com/1268555",[88],[90],{"url":136,"sources":137,"tags":138},"https://bugzilla.suse.com/1268592",[88],[90],{"url":140,"sources":141,"tags":142},"https://bugzilla.suse.com/1268593",[88],[90],{"url":144,"sources":145,"tags":146},"https://bugzilla.suse.com/1268598",[88],[90],{"url":148,"sources":149,"tags":150},"https://bugzilla.suse.com/1268605",[88],[90],{"url":152,"sources":153,"tags":154},"https://bugzilla.suse.com/1268606",[88],[90],{"url":156,"sources":157,"tags":158},"https://bugzilla.suse.com/1268608",[88],[90],{"url":160,"sources":161,"tags":162},"https://bugzilla.suse.com/1268609",[88],[90],{"url":164,"sources":165,"tags":166},"https://bugzilla.suse.com/1268611",[88],[90],{"url":168,"sources":169,"tags":170},"https://bugzilla.suse.com/1268618",[88],[90],{"url":172,"sources":173,"tags":174},"https://bugzilla.suse.com/1269825",[88],[90],{"url":176,"sources":177,"tags":178},"https://www.suse.com/security/cve/CVE-2026-11525",[88],[179],"WEB",{"url":181,"sources":182,"tags":183},"https://www.suse.com/security/cve/CVE-2026-12151",[88],[179],{"url":185,"sources":186,"tags":187},"https://www.suse.com/security/cve/CVE-2026-2581",[88],[179],{"url":189,"sources":190,"tags":191},"https://www.suse.com/security/cve/CVE-2026-27135",[88],[179],{"url":193,"sources":194,"tags":195},"https://www.suse.com/security/cve/CVE-2026-40170",[88],[179],{"url":197,"sources":198,"tags":199},"https://www.suse.com/security/cve/CVE-2026-42338",[88],[179],{"url":201,"sources":202,"tags":203},"https://www.suse.com/security/cve/CVE-2026-48615",[88],[179],{"url":205,"sources":206,"tags":207},"https://www.suse.com/security/cve/CVE-2026-48617",[88],[179],{"url":209,"sources":210,"tags":211},"https://www.suse.com/security/cve/CVE-2026-48618",[88],[179],{"url":213,"sources":214,"tags":215},"https://www.suse.com/security/cve/CVE-2026-48619",[88],[179],{"url":217,"sources":218,"tags":219},"https://www.suse.com/security/cve/CVE-2026-48928",[88],[179],{"url":221,"sources":222,"tags":223},"https://www.suse.com/security/cve/CVE-2026-48930",[88],[179],{"url":225,"sources":226,"tags":227},"https://www.suse.com/security/cve/CVE-2026-48931",[88],[179],{"url":229,"sources":230,"tags":231},"https://www.suse.com/security/cve/CVE-2026-48933",[88],[179],{"url":233,"sources":234,"tags":235},"https://www.suse.com/security/cve/CVE-2026-48934",[88],[179],{"url":237,"sources":238,"tags":239},"https://www.suse.com/security/cve/CVE-2026-48935",[88],[179],{"url":241,"sources":242,"tags":243},"https://www.suse.com/security/cve/CVE-2026-48937",[88],[179],{"url":245,"sources":246,"tags":247},"https://www.suse.com/security/cve/CVE-2026-6733",[88],[179],{"url":249,"sources":250,"tags":251},"https://www.suse.com/security/cve/CVE-2026-9496",[88],[179],{"url":253,"sources":254,"tags":255},"https://www.suse.com/security/cve/CVE-2026-9678",[88],[179],{"url":257,"sources":258,"tags":259},"https://www.suse.com/security/cve/CVE-2026-9679",[88],[179],[],[],[],[264],{"ecosystem":265,"name":266,"vendor":267,"product":268,"cpe_part":9,"purl_type":269,"purl_namespace":267,"purl_name":268,"source":9,"versions":270},"openSUSE","nodejs24","opensuse","nodejs24&distro=openSUSE Leap 16.0","rpm",[271],{"version":272,"is_range":273,"range_type":274,"version_start":9,"version_start_type":9,"version_end":275,"version_end_type":276,"fixed_in":9},"lt24_18_0_160000_1_1",true,"ecosystem","24.18.0-160000.1.1","excluding"]