[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-SUSE-SU-2026:3929-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T17:35:29.592Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":84,"duplicates":85,"related":86,"reserved_at":9,"published_at":122,"modified_at":123,"state":9,"summary":124,"references_raw":126,"kevs":419,"epss":9,"epss_history":420,"metrics":421,"affected":422},"SUSE-SU-2026:3929-1","Security update for nodejs20\n\nThis update for nodejs20 fixes the following issues:\n\n- CVE-2025-22150: undici: predictable random values used when defining the boundary for a `multipart`/`form-data`\n  request (bsc#1236258).\n- CVE-2026-6733: undici: response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery\n  (bsc#1268479).\n- CVE-2026-9496: pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec`\n  value can lead to DoS (bsc#1266318).\n- CVE-2026-9679: undici: HTTP header injection via `Set-Cookie` percent-decoding (bsc#1268477).\n- CVE-2026-11525: undici: weakening of cookie `SameSite` policy due to incorrect parsing of `Set-Cookie` header\n  (bsc#1268481).\n- CVE-2026-12151: undici: denial of service due to unbounded memory growth via WebSocket frames (bsc#1268482).\n- CVE-2026-16728: undici: downstream response desynchronization via retry interceptor (bsc#1273593).\n- CVE-2026-16729: undici: `setCookie` function does not fully sanitize cookie attributes (bsc#1273591).\n- CVE-2026-22036: undici: unbounded decompression chain in HTTP responses via `Content-Encoding` may lead to resource\n  exhaustion (bsc#1256848).\n- CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853).\n- CVE-2026-40170: ngtcp2: qlog `parameters_set` stack buffer overflow (bsc#1262274).\n- CVE-2026-42338: ip-address: cross-site scripting via improper HTML escaping of untrusted input (bsc#1268097).\n- CVE-2026-48615: proxy credentials leaked in `ERR_PROXY_TUNNEL` error message (bsc#1268598).\n- CVE-2026-48617: permission model enforcement bypass via `process.report.writeReport()` path misvalidation\n  (bsc#1268554).\n- CVE-2026-48618: unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to\n  resolver and verifier hostname normalization mismatch (bsc#1268593).\n- CVE-2026-48619: unbounded memory growth in `node:http2` clients via attacker-controlled `ORIGIN` frames (bsc#1268618).\n- CVE-2026-48928: uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname\n  matching (bsc#1268605).\n- CVE-2026-48930: `embedded-nul` hostnames can lead to silent authority rebinding due to `c-string` truncation in\n  resolver bindings (bsc#1268606).\n- CVE-2026-48931: HTTP response queue poisoning via TOCTOU race condition in `http.Agent` (bsc#1268611).\n- CVE-2026-48933: WebCrypto AES integer overflow leads to remote process abort (bsc#1268592).\n- CVE-2026-48934: TLS host identity verification bypass via session reuse with different servername leads to\n  unauthorized connections (bsc#1268608).\n- CVE-2026-48935: permission model bypass via `FileHandle.utimes()` in the `promises` API (bsc#1268609).\n- CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555).\n- CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust-\n  boundary checks (bsc#1272882).\n- CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941).\n- CVE-2026-56847: permission model allows trace events to write outside the allowlist (bsc#1272949).\n- CVE-2026-56848: HTTP/2 re-entrant send can cause heap use-after-free (bsc#1272942).\n- CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944).\n- CVE-2026-58039: permission model allows process reports to write outside the allowlist (bsc#1272950).\n- CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945).\n- CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many `A` records (bsc#1272947).\n- CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943).\n- CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951).\n- CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948).\n- CVE-2026-69192: ip-address: `Address4` decodes leading-zero octets as decimal while resolvers decode them as octal,\n  which allows for SSRF and trust-boundary bypass (bsc#1277587).\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64,66,68,70,72,74,76,78,80,82],{"_key":15},"CVE-2025-22150",{"_key":17},"CVE-2026-11525",{"_key":19},"CVE-2026-12151",{"_key":21},"CVE-2026-16728",{"_key":23},"CVE-2026-16729",{"_key":25},"CVE-2026-22036",{"_key":27},"CVE-2026-27135",{"_key":29},"CVE-2026-40170",{"_key":31},"CVE-2026-42338",{"_key":33},"CVE-2026-48615",{"_key":35},"CVE-2026-48617",{"_key":37},"CVE-2026-48618",{"_key":39},"CVE-2026-48619",{"_key":41},"CVE-2026-48928",{"_key":43},"CVE-2026-48930",{"_key":45},"CVE-2026-48931",{"_key":47},"CVE-2026-48933",{"_key":49},"CVE-2026-48934",{"_key":51},"CVE-2026-48935",{"_key":53},"CVE-2026-48937",{"_key":55},"CVE-2026-54272",{"_key":57},"CVE-2026-56846",{"_key":59},"CVE-2026-56847",{"_key":61},"CVE-2026-56848",{"_key":63},"CVE-2026-56850",{"_key":65},"CVE-2026-58039",{"_key":67},"CVE-2026-58040",{"_key":69},"CVE-2026-58042",{"_key":71},"CVE-2026-58043",{"_key":73},"CVE-2026-58044",{"_key":75},"CVE-2026-58045",{"_key":77},"CVE-2026-6733",{"_key":79},"CVE-2026-69192",{"_key":81},"CVE-2026-9496",{"_key":83},"CVE-2026-9679",[],[],[87,88,89,90,91,92,93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":55},{"_key":57},{"_key":59},{"_key":61},{"_key":63},{"_key":65},{"_key":67},{"_key":69},{"_key":71},{"_key":73},{"_key":75},{"_key":77},{"_key":79},{"_key":81},{"_key":83},"2026-09-03T07:18:06Z","2026-09-10T18:23:21.565514799Z",{"cisa_kev":125,"cisa_ransomware":125,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[127,133,138,142,146,150,154,158,162,166,170,174,178,182,186,190,194,198,202,206,210,214,218,222,226,230,234,238,242,246,250,254,258,262,266,270,274,278,283,287,291,295,299,303,307,311,315,319,323,327,331,335,339,343,347,351,355,359,363,367,371,375,379,383,387,391,395,399,403,407,411,415],{"url":128,"sources":129,"tags":131},"https://www.suse.com/support/update/announcement/2026/suse-su-20263929-1/",[130],"osv_suse",[132],"Advisory",{"url":134,"sources":135,"tags":136},"https://bugzilla.suse.com/1236258",[130],[137],"REPORT",{"url":139,"sources":140,"tags":141},"https://bugzilla.suse.com/1256848",[130],[137],{"url":143,"sources":144,"tags":145},"https://bugzilla.suse.com/1259853",[130],[137],{"url":147,"sources":148,"tags":149},"https://bugzilla.suse.com/1262274",[130],[137],{"url":151,"sources":152,"tags":153},"https://bugzilla.suse.com/1266318",[130],[137],{"url":155,"sources":156,"tags":157},"https://bugzilla.suse.com/1268097",[130],[137],{"url":159,"sources":160,"tags":161},"https://bugzilla.suse.com/1268477",[130],[137],{"url":163,"sources":164,"tags":165},"https://bugzilla.suse.com/1268479",[130],[137],{"url":167,"sources":168,"tags":169},"https://bugzilla.suse.com/1268481",[130],[137],{"url":171,"sources":172,"tags":173},"https://bugzilla.suse.com/1268482",[130],[137],{"url":175,"sources":176,"tags":177},"https://bugzilla.suse.com/1268554",[130],[137],{"url":179,"sources":180,"tags":181},"https://bugzilla.suse.com/1268555",[130],[137],{"url":183,"sources":184,"tags":185},"https://bugzilla.suse.com/1268592",[130],[137],{"url":187,"sources":188,"tags":189},"https://bugzilla.suse.com/1268593",[130],[137],{"url":191,"sources":192,"tags":193},"https://bugzilla.suse.com/1268598",[130],[137],{"url":195,"sources":196,"tags":197},"https://bugzilla.suse.com/1268605",[130],[137],{"url":199,"sources":200,"tags":201},"https://bugzilla.suse.com/1268606",[130],[137],{"url":203,"sources":204,"tags":205},"https://bugzilla.suse.com/1268608",[130],[137],{"url":207,"sources":208,"tags":209},"https://bugzilla.suse.com/1268609",[130],[137],{"url":211,"sources":212,"tags":213},"https://bugzilla.suse.com/1268611",[130],[137],{"url":215,"sources":216,"tags":217},"https://bugzilla.suse.com/1268618",[130],[137],{"url":219,"sources":220,"tags":221},"https://bugzilla.suse.com/1269825",[130],[137],{"url":223,"sources":224,"tags":225},"https://bugzilla.suse.com/1272882",[130],[137],{"url":227,"sources":228,"tags":229},"https://bugzilla.suse.com/1272941",[130],[137],{"url":231,"sources":232,"tags":233},"https://bugzilla.suse.com/1272942",[130],[137],{"url":235,"sources":236,"tags":237},"https://bugzilla.suse.com/1272943",[130],[137],{"url":239,"sources":240,"tags":241},"https://bugzilla.suse.com/1272944",[130],[137],{"url":243,"sources":244,"tags":245},"https://bugzilla.suse.com/1272945",[130],[137],{"url":247,"sources":248,"tags":249},"https://bugzilla.suse.com/1272947",[130],[137],{"url":251,"sources":252,"tags":253},"https://bugzilla.suse.com/1272948",[130],[137],{"url":255,"sources":256,"tags":257},"https://bugzilla.suse.com/1272949",[130],[137],{"url":259,"sources":260,"tags":261},"https://bugzilla.suse.com/1272950",[130],[137],{"url":263,"sources":264,"tags":265},"https://bugzilla.suse.com/1272951",[130],[137],{"url":267,"sources":268,"tags":269},"https://bugzilla.suse.com/1273591",[130],[137],{"url":271,"sources":272,"tags":273},"https://bugzilla.suse.com/1273593",[130],[137],{"url":275,"sources":276,"tags":277},"https://bugzilla.suse.com/1277587",[130],[137],{"url":279,"sources":280,"tags":281},"https://www.suse.com/security/cve/CVE-2025-22150",[130],[282],"WEB",{"url":284,"sources":285,"tags":286},"https://www.suse.com/security/cve/CVE-2026-11525",[130],[282],{"url":288,"sources":289,"tags":290},"https://www.suse.com/security/cve/CVE-2026-12151",[130],[282],{"url":292,"sources":293,"tags":294},"https://www.suse.com/security/cve/CVE-2026-16728",[130],[282],{"url":296,"sources":297,"tags":298},"https://www.suse.com/security/cve/CVE-2026-16729",[130],[282],{"url":300,"sources":301,"tags":302},"https://www.suse.com/security/cve/CVE-2026-22036",[130],[282],{"url":304,"sources":305,"tags":306},"https://www.suse.com/security/cve/CVE-2026-27135",[130],[282],{"url":308,"sources":309,"tags":310},"https://www.suse.com/security/cve/CVE-2026-40170",[130],[282],{"url":312,"sources":313,"tags":314},"https://www.suse.com/security/cve/CVE-2026-42338",[130],[282],{"url":316,"sources":317,"tags":318},"https://www.suse.com/security/cve/CVE-2026-48615",[130],[282],{"url":320,"sources":321,"tags":322},"https://www.suse.com/security/cve/CVE-2026-48617",[130],[282],{"url":324,"sources":325,"tags":326},"https://www.suse.com/security/cve/CVE-2026-48618",[130],[282],{"url":328,"sources":329,"tags":330},"https://www.suse.com/security/cve/CVE-2026-48619",[130],[282],{"url":332,"sources":333,"tags":334},"https://www.suse.com/security/cve/CVE-2026-48928",[130],[282],{"url":336,"sources":337,"tags":338},"https://www.suse.com/security/cve/CVE-2026-48930",[130],[282],{"url":340,"sources":341,"tags":342},"https://www.suse.com/security/cve/CVE-2026-48931",[130],[282],{"url":344,"sources":345,"tags":346},"https://www.suse.com/security/cve/CVE-2026-48933",[130],[282],{"url":348,"sources":349,"tags":350},"https://www.suse.com/security/cve/CVE-2026-48934",[130],[282],{"url":352,"sources":353,"tags":354},"https://www.suse.com/security/cve/CVE-2026-48935",[130],[282],{"url":356,"sources":357,"tags":358},"https://www.suse.com/security/cve/CVE-2026-48937",[130],[282],{"url":360,"sources":361,"tags":362},"https://www.suse.com/security/cve/CVE-2026-54272",[130],[282],{"url":364,"sources":365,"tags":366},"https://www.suse.com/security/cve/CVE-2026-56846",[130],[282],{"url":368,"sources":369,"tags":370},"https://www.suse.com/security/cve/CVE-2026-56847",[130],[282],{"url":372,"sources":373,"tags":374},"https://www.suse.com/security/cve/CVE-2026-56848",[130],[282],{"url":376,"sources":377,"tags":378},"https://www.suse.com/security/cve/CVE-2026-56850",[130],[282],{"url":380,"sources":381,"tags":382},"https://www.suse.com/security/cve/CVE-2026-58039",[130],[282],{"url":384,"sources":385,"tags":386},"https://www.suse.com/security/cve/CVE-2026-58040",[130],[282],{"url":388,"sources":389,"tags":390},"https://www.suse.com/security/cve/CVE-2026-58042",[130],[282],{"url":392,"sources":393,"tags":394},"https://www.suse.com/security/cve/CVE-2026-58043",[130],[282],{"url":396,"sources":397,"tags":398},"https://www.suse.com/security/cve/CVE-2026-58044",[130],[282],{"url":400,"sources":401,"tags":402},"https://www.suse.com/security/cve/CVE-2026-58045",[130],[282],{"url":404,"sources":405,"tags":406},"https://www.suse.com/security/cve/CVE-2026-6733",[130],[282],{"url":408,"sources":409,"tags":410},"https://www.suse.com/security/cve/CVE-2026-69192",[130],[282],{"url":412,"sources":413,"tags":414},"https://www.suse.com/security/cve/CVE-2026-9496",[130],[282],{"url":416,"sources":417,"tags":418},"https://www.suse.com/security/cve/CVE-2026-9679",[130],[282],[],[],[],[423,436],{"ecosystem":424,"name":425,"vendor":426,"product":427,"cpe_part":9,"purl_type":428,"purl_namespace":426,"purl_name":427,"source":9,"versions":429},"SUSE Linux Enterprise","nodejs20","suse","nodejs20&distro=SUSE Linux Enterprise Server 15 SP6-LTSS","rpm",[430],{"version":431,"is_range":432,"range_type":433,"version_start":9,"version_start_type":9,"version_end":434,"version_end_type":435,"fixed_in":9},"lt20_20_2_150600_3_21_1",true,"ecosystem","20.20.2-150600.3.21.1","excluding",{"ecosystem":424,"name":425,"vendor":426,"product":437,"cpe_part":9,"purl_type":428,"purl_namespace":426,"purl_name":437,"source":9,"versions":438},"nodejs20&distro=SUSE Linux Enterprise Server for SAP Applications 15 SP6",[439],{"version":431,"is_range":432,"range_type":433,"version_start":9,"version_start_type":9,"version_end":434,"version_end_type":435,"fixed_in":9}]