[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-OPENSUSE-SU-2026:21546-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T11:35:27.363Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":38,"duplicates":39,"related":40,"reserved_at":9,"published_at":53,"modified_at":54,"state":9,"summary":55,"references_raw":57,"kevs":157,"epss":9,"epss_history":158,"metrics":159,"affected":160},"OPENSUSE-SU-2026:21546-1","Security update for nodejs24\n\nThis update for nodejs24 fixes the following issues:\n\nUpdate to 24.18.1.\n\n- CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust-\n  boundary checks (bsc#1272882).\n- CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941).\n- CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949).\n- CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942).\n- CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944).\n- CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950).\n- CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945).\n- CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many A records (bsc#1272947).\n- CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943).\n- CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951).\n- CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948).\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36],{"_key":15},"CVE-2026-54272",{"_key":17},"CVE-2026-56846",{"_key":19},"CVE-2026-56847",{"_key":21},"CVE-2026-56848",{"_key":23},"CVE-2026-56850",{"_key":25},"CVE-2026-58039",{"_key":27},"CVE-2026-58040",{"_key":29},"CVE-2026-58041",{"_key":31},"CVE-2026-58042",{"_key":33},"CVE-2026-58043",{"_key":35},"CVE-2026-58044",{"_key":37},"CVE-2026-58045",[],[],[41,42,43,44,45,46,47,48,49,50,51,52],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},"2026-08-10T09:28:21Z","2026-08-12T18:23:41.522498755Z",{"cisa_kev":56,"cisa_ransomware":56,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[58,64,68,72,76,80,84,88,92,96,100,104,108,113,117,121,125,129,133,137,141,145,149,153],{"url":59,"sources":60,"tags":62},"https://bugzilla.suse.com/1272882",[61],"osv_opensuse",[63],"REPORT",{"url":65,"sources":66,"tags":67},"https://bugzilla.suse.com/1272941",[61],[63],{"url":69,"sources":70,"tags":71},"https://bugzilla.suse.com/1272942",[61],[63],{"url":73,"sources":74,"tags":75},"https://bugzilla.suse.com/1272943",[61],[63],{"url":77,"sources":78,"tags":79},"https://bugzilla.suse.com/1272944",[61],[63],{"url":81,"sources":82,"tags":83},"https://bugzilla.suse.com/1272945",[61],[63],{"url":85,"sources":86,"tags":87},"https://bugzilla.suse.com/1272946",[61],[63],{"url":89,"sources":90,"tags":91},"https://bugzilla.suse.com/1272947",[61],[63],{"url":93,"sources":94,"tags":95},"https://bugzilla.suse.com/1272948",[61],[63],{"url":97,"sources":98,"tags":99},"https://bugzilla.suse.com/1272949",[61],[63],{"url":101,"sources":102,"tags":103},"https://bugzilla.suse.com/1272950",[61],[63],{"url":105,"sources":106,"tags":107},"https://bugzilla.suse.com/1272951",[61],[63],{"url":109,"sources":110,"tags":111},"https://www.suse.com/security/cve/CVE-2026-54272",[61],[112],"WEB",{"url":114,"sources":115,"tags":116},"https://www.suse.com/security/cve/CVE-2026-56846",[61],[112],{"url":118,"sources":119,"tags":120},"https://www.suse.com/security/cve/CVE-2026-56847",[61],[112],{"url":122,"sources":123,"tags":124},"https://www.suse.com/security/cve/CVE-2026-56848",[61],[112],{"url":126,"sources":127,"tags":128},"https://www.suse.com/security/cve/CVE-2026-56850",[61],[112],{"url":130,"sources":131,"tags":132},"https://www.suse.com/security/cve/CVE-2026-58039",[61],[112],{"url":134,"sources":135,"tags":136},"https://www.suse.com/security/cve/CVE-2026-58040",[61],[112],{"url":138,"sources":139,"tags":140},"https://www.suse.com/security/cve/CVE-2026-58041",[61],[112],{"url":142,"sources":143,"tags":144},"https://www.suse.com/security/cve/CVE-2026-58042",[61],[112],{"url":146,"sources":147,"tags":148},"https://www.suse.com/security/cve/CVE-2026-58043",[61],[112],{"url":150,"sources":151,"tags":152},"https://www.suse.com/security/cve/CVE-2026-58044",[61],[112],{"url":154,"sources":155,"tags":156},"https://www.suse.com/security/cve/CVE-2026-58045",[61],[112],[],[],[],[161],{"ecosystem":162,"name":163,"vendor":164,"product":165,"cpe_part":9,"purl_type":166,"purl_namespace":164,"purl_name":165,"source":9,"versions":167},"openSUSE","nodejs24","opensuse","nodejs24&distro=openSUSE Leap 16.0","rpm",[168],{"version":169,"is_range":170,"range_type":171,"version_start":9,"version_start_type":9,"version_end":172,"version_end_type":173,"fixed_in":9},"lt24_18_1_160000_1_1",true,"ecosystem","24.18.1-160000.1.1","excluding"]