OPENSUSE-SU-2026:21545-1
Vulnerability Summary
Timeline
Description
Security update for nodejs22 This update for nodejs22 fixes the following issues: Update to 22.23.2. - CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust- boundary checks (bsc#1272882). - CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941). - CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949). - CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942). - CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944). - CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950). - CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945). - CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many A records (bsc#1272947). - CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943). - CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951). - CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948).
Affected Systems
- opensuse•nodejs22&distro=openSUSE Leap 16.0
< 22.23.2-160000.1.1
References (22)
- https://bugzilla.suse.com/1272882
- https://bugzilla.suse.com/1272941
- https://bugzilla.suse.com/1272942
- https://bugzilla.suse.com/1272943
- https://bugzilla.suse.com/1272944
- https://bugzilla.suse.com/1272945
- https://bugzilla.suse.com/1272947
- https://bugzilla.suse.com/1272948
- https://bugzilla.suse.com/1272949
- https://bugzilla.suse.com/1272950
- https://bugzilla.suse.com/1272951
- https://www.suse.com/security/cve/CVE-2026-54272
- https://www.suse.com/security/cve/CVE-2026-56846
- https://www.suse.com/security/cve/CVE-2026-56847
- https://www.suse.com/security/cve/CVE-2026-56848
- https://www.suse.com/security/cve/CVE-2026-56850
- https://www.suse.com/security/cve/CVE-2026-58039
- https://www.suse.com/security/cve/CVE-2026-58040
- https://www.suse.com/security/cve/CVE-2026-58042
- https://www.suse.com/security/cve/CVE-2026-58043
- https://www.suse.com/security/cve/CVE-2026-58044
- https://www.suse.com/security/cve/CVE-2026-58045