OPENSUSE-SU-2026:21545-1

Advisory lineage Upstream: 11 Downstream: 0
Published: 10 Aug 2026, 09:02
Last modified:12 Aug 2026, 18:23

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Aug 2026, 09:02
Published
Vulnerability first disclosed
12 Aug 2026, 18:23
Last Modified
Vulnerability information updated

Description

Security update for nodejs22 This update for nodejs22 fixes the following issues: Update to 22.23.2. - CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust- boundary checks (bsc#1272882). - CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941). - CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949). - CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942). - CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944). - CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950). - CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945). - CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many A records (bsc#1272947). - CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943). - CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951). - CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948).

Affected Systems

  • opensusenodejs22&distro=openSUSE Leap 16.0

    < 22.23.2-160000.1.1

References (22)