[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21545-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":36,"duplicates":37,"related":38,"reserved_at":9,"published_at":50,"modified_at":51,"state":9,"summary":52,"references_raw":54,"kevs":146,"epss":9,"epss_history":147,"metrics":148,"affected":149},"OPENSUSE-SU-2026:21545-1","Security update for nodejs22\n\nThis update for nodejs22 fixes the following issues:\n\nUpdate to 22.23.2.\n\n- CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust-\n  boundary checks (bsc#1272882).\n- CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941).\n- CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949).\n- CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942).\n- CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944).\n- CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950).\n- CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945).\n- CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many A records (bsc#1272947).\n- CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943).\n- CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951).\n- CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948).\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34],{"_key":15},"CVE-2026-54272",{"_key":17},"CVE-2026-56846",{"_key":19},"CVE-2026-56847",{"_key":21},"CVE-2026-56848",{"_key":23},"CVE-2026-56850",{"_key":25},"CVE-2026-58039",{"_key":27},"CVE-2026-58040",{"_key":29},"CVE-2026-58042",{"_key":31},"CVE-2026-58043",{"_key":33},"CVE-2026-58044",{"_key":35},"CVE-2026-58045",[],[],[39,40,41,42,43,44,45,46,47,48,49],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},"2026-08-10T09:02:01Z","2026-08-12T18:23:41.474952932Z",{"cisa_kev":53,"cisa_ransomware":53,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[55,61,65,69,73,77,81,85,89,93,97,101,106,110,114,118,122,126,130,134,138,142],{"url":56,"sources":57,"tags":59},"https://bugzilla.suse.com/1272882",[58],"osv_opensuse",[60],"REPORT",{"url":62,"sources":63,"tags":64},"https://bugzilla.suse.com/1272941",[58],[60],{"url":66,"sources":67,"tags":68},"https://bugzilla.suse.com/1272942",[58],[60],{"url":70,"sources":71,"tags":72},"https://bugzilla.suse.com/1272943",[58],[60],{"url":74,"sources":75,"tags":76},"https://bugzilla.suse.com/1272944",[58],[60],{"url":78,"sources":79,"tags":80},"https://bugzilla.suse.com/1272945",[58],[60],{"url":82,"sources":83,"tags":84},"https://bugzilla.suse.com/1272947",[58],[60],{"url":86,"sources":87,"tags":88},"https://bugzilla.suse.com/1272948",[58],[60],{"url":90,"sources":91,"tags":92},"https://bugzilla.suse.com/1272949",[58],[60],{"url":94,"sources":95,"tags":96},"https://bugzilla.suse.com/1272950",[58],[60],{"url":98,"sources":99,"tags":100},"https://bugzilla.suse.com/1272951",[58],[60],{"url":102,"sources":103,"tags":104},"https://www.suse.com/security/cve/CVE-2026-54272",[58],[105],"WEB",{"url":107,"sources":108,"tags":109},"https://www.suse.com/security/cve/CVE-2026-56846",[58],[105],{"url":111,"sources":112,"tags":113},"https://www.suse.com/security/cve/CVE-2026-56847",[58],[105],{"url":115,"sources":116,"tags":117},"https://www.suse.com/security/cve/CVE-2026-56848",[58],[105],{"url":119,"sources":120,"tags":121},"https://www.suse.com/security/cve/CVE-2026-56850",[58],[105],{"url":123,"sources":124,"tags":125},"https://www.suse.com/security/cve/CVE-2026-58039",[58],[105],{"url":127,"sources":128,"tags":129},"https://www.suse.com/security/cve/CVE-2026-58040",[58],[105],{"url":131,"sources":132,"tags":133},"https://www.suse.com/security/cve/CVE-2026-58042",[58],[105],{"url":135,"sources":136,"tags":137},"https://www.suse.com/security/cve/CVE-2026-58043",[58],[105],{"url":139,"sources":140,"tags":141},"https://www.suse.com/security/cve/CVE-2026-58044",[58],[105],{"url":143,"sources":144,"tags":145},"https://www.suse.com/security/cve/CVE-2026-58045",[58],[105],[],[],[],[150],{"ecosystem":151,"name":152,"vendor":153,"product":154,"cpe_part":9,"purl_type":155,"purl_namespace":153,"purl_name":154,"source":9,"versions":156},"openSUSE","nodejs22","opensuse","nodejs22&distro=openSUSE Leap 16.0","rpm",[157],{"version":158,"is_range":159,"range_type":160,"version_start":9,"version_start_type":9,"version_end":161,"version_end_type":162,"fixed_in":9},"lt22_23_2_160000_1_1",true,"ecosystem","22.23.2-160000.1.1","excluding"]