[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-SUSE-SU-2026:4248-1":6},{"stargazers_count":4,"fetched_at":5},8,"2026-09-19T17:35:29.592Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":11,"aliases":12,"duplicate_of":9,"upstream":13,"downstream":90,"duplicates":91,"related":92,"reserved_at":9,"published_at":131,"modified_at":132,"state":9,"summary":133,"references_raw":135,"kevs":452,"epss":9,"epss_history":453,"metrics":454,"affected":455},"SUSE-SU-2026:4248-1","Security update for nodejs18\n\nThis update for nodejs18 fixes the following issues:\n\n- CVE-2025-22150: undici: insufficiently random values used when defining the boundary for a multipart/form-data request\n  (bsc#1236258).\n- CVE-2025-23166: improper error handling in async cryptographic operations crashes process (bsc#1243218).\n- CVE-2025-23167: llhttp: improper HTTP header block termination in llhttp (bsc#1243220).\n- CVE-2025-55131: timeout-based race conditions allow for allocations that contain leftover data from previous\n  operations and lead to exposure of in-process secrets (bsc#1256570).\n- CVE-2025-59465: malformed HTTP/2 HEADERS frame with invalid HPACK data can cause a crash due to an unhandled error\n  (bsc#1256573).\n- CVE-2025-59466: uncatchable 'Maximum call stack size exceeded' error when `async_hooks.createHook()` is enabled can\n  lead to crash (bsc#1256574).\n- CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free() (bsc#1254738).\n- CVE-2026-6733: undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response\n  delivery (bsc#1268479).\n- CVE-2026-9679: undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding (bsc#1268477).\n- CVE-2026-11525: undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header\n  (bsc#1268481).\n- CVE-2026-12151: undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (bsc#1268482).\n- CVE-2026-15157: No validation of the type property of a duck-typed blob-like request body before using it as the\n  Content-Type header on the HTTP/1.1 dispatcher (bsc#1272958).\n- CVE-2026-16728: undici: downstream response desynchronization via retry interceptor (bsc#1273593).\n- CVE-2026-16729: undici: undici's setCookie function does not fully sanitize cookie attributes (bsc#1273591).\n- CVE-2026-21637: synchronous exceptions thrown during certain callbacks bypass the standard TLS error handling paths\n  and can cause a denial of service (bsc#1256576).\n- CVE-2026-21710: uncaught TypeError exception can cause a denial of service (bsc#1260455).\n- CVE-2026-21713: timing side-channel in HMAC verification via memcmp can lead to potential MAC forgery (bsc#1260463).\n- CVE-2026-21714: WINDOW_UPDATE frames on stream 0 can lead to memory leak (bsc#1260480).\n- CVE-2026-21717: crafted request can lead to hash collisions trivially predictable (bsc#1260494).\n- CVE-2026-22036: undici: unbounded decompression chain in HTTP responses via Content-Encoding may lead to resource\n  exhaustion (bsc#1256848).\n- CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853).\n- CVE-2026-48618: Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to\n  resolver and verifier hostname normalization mismatch (bsc#1268593).\n- CVE-2026-48619: Unbounded memory growth in node:http2 clients via attacker-controlled ORIGIN frames (bsc#1268618).\n- CVE-2026-48928: Uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname\n  matching (bsc#1268605).\n- CVE-2026-48930: Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver\n  bindings (bsc#1268606).\n- CVE-2026-48931: HTTP Response Queue Poisoning via TOCTOU Race Condition in http.Agent (bsc#1268611).\n- CVE-2026-48933: Node.js WebCrypto AES Integer Overflow Leads to Remote Process Abort (bsc#1268592).\n- CVE-2026-48934: TLS host identity verification bypass via session reuse with different servername leads to\n  unauthorized connections (bsc#1268608).\n- CVE-2026-48935: Permission Model bypass via FileHandle.utimes() in the promises API (bsc#1268609).\n- CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555).\n- CVE-2026-56846: HTTP/2 retained headers can bypass maxSessionMemory limits (bsc#1272941).\n- CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942).\n- CVE-2026-56850: HTTPS Agent can reuse mTLS identities across PFX certificates (bsc#1272944).\n- CVE-2026-58040: HTTPS Agent session reuse can skip hostname verification (bsc#1272945).\n- CVE-2026-58042: dns.resolveAny() can abort on DNS responses with many A records (bsc#1272947).\n- CVE-2026-58043: Permission Model path matching can over-grant filesystem access (bsc#1272943).\n- CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951).\n- CVE-2026-58045: node:zlib sync APIs can crash on spoofed TypedArray length (bsc#1272948).\n\nChanges for nodejs18:\n \n- upgraded embedded undici to 6.28.0.\n- upgraded embedded nghttp2 to 1.69.0.\n",null,[],[],[],[14,16,18,20,22,24,26,28,30,32,34,36,38,40,42,44,46,48,50,52,54,56,58,60,62,64,66,68,70,72,74,76,78,80,82,84,86,88],{"_key":15},"CVE-2025-22150",{"_key":17},"CVE-2025-23166",{"_key":19},"CVE-2025-23167",{"_key":21},"CVE-2025-55131",{"_key":23},"CVE-2025-59465",{"_key":25},"CVE-2025-59466",{"_key":27},"CVE-2025-62408",{"_key":29},"CVE-2026-11525",{"_key":31},"CVE-2026-12151",{"_key":33},"CVE-2026-15157",{"_key":35},"CVE-2026-16728",{"_key":37},"CVE-2026-16729",{"_key":39},"CVE-2026-21637",{"_key":41},"CVE-2026-21710",{"_key":43},"CVE-2026-21713",{"_key":45},"CVE-2026-21714",{"_key":47},"CVE-2026-21717",{"_key":49},"CVE-2026-22036",{"_key":51},"CVE-2026-27135",{"_key":53},"CVE-2026-48618",{"_key":55},"CVE-2026-48619",{"_key":57},"CVE-2026-48928",{"_key":59},"CVE-2026-48930",{"_key":61},"CVE-2026-48931",{"_key":63},"CVE-2026-48933",{"_key":65},"CVE-2026-48934",{"_key":67},"CVE-2026-48935",{"_key":69},"CVE-2026-48937",{"_key":71},"CVE-2026-56846",{"_key":73},"CVE-2026-56848",{"_key":75},"CVE-2026-56850",{"_key":77},"CVE-2026-58040",{"_key":79},"CVE-2026-58042",{"_key":81},"CVE-2026-58043",{"_key":83},"CVE-2026-58044",{"_key":85},"CVE-2026-58045",{"_key":87},"CVE-2026-6733",{"_key":89},"CVE-2026-9679",[],[],[93,94,95,96,97,98,99,100,101,102,103,104,105,106,107,108,109,110,111,112,113,114,115,116,117,118,119,120,121,122,123,124,125,126,127,128,129,130],{"_key":15},{"_key":17},{"_key":19},{"_key":21},{"_key":23},{"_key":25},{"_key":27},{"_key":29},{"_key":31},{"_key":33},{"_key":35},{"_key":37},{"_key":39},{"_key":41},{"_key":43},{"_key":45},{"_key":47},{"_key":49},{"_key":51},{"_key":53},{"_key":55},{"_key":57},{"_key":59},{"_key":61},{"_key":63},{"_key":65},{"_key":67},{"_key":69},{"_key":71},{"_key":73},{"_key":75},{"_key":77},{"_key":79},{"_key":81},{"_key":83},{"_key":85},{"_key":87},{"_key":89},"2026-09-17T15:59:50Z","2026-09-18T10:00:04.762818452Z",{"cisa_kev":134,"cisa_ransomware":134,"cisa_vendor":9,"epss_severity":9,"epss_score":9,"severity":9,"severity_score":9,"severity_version":9,"severity_source":9,"severity_vector":9,"severity_status":9},false,[136,142,147,151,155,159,163,167,171,175,179,183,187,191,195,199,203,207,211,215,219,223,227,231,235,239,243,247,251,255,259,263,267,271,275,279,283,287,291,295,299,304,308,312,316,320,324,328,332,336,340,344,348,352,356,360,364,368,372,376,380,384,388,392,396,400,404,408,412,416,420,424,428,432,436,440,444,448],{"url":137,"sources":138,"tags":140},"https://www.suse.com/support/update/announcement/2026/suse-su-20264248-1/",[139],"osv_suse",[141],"Advisory",{"url":143,"sources":144,"tags":145},"https://bugzilla.suse.com/1236258",[139],[146],"REPORT",{"url":148,"sources":149,"tags":150},"https://bugzilla.suse.com/1243218",[139],[146],{"url":152,"sources":153,"tags":154},"https://bugzilla.suse.com/1243220",[139],[146],{"url":156,"sources":157,"tags":158},"https://bugzilla.suse.com/1254738",[139],[146],{"url":160,"sources":161,"tags":162},"https://bugzilla.suse.com/1256570",[139],[146],{"url":164,"sources":165,"tags":166},"https://bugzilla.suse.com/1256573",[139],[146],{"url":168,"sources":169,"tags":170},"https://bugzilla.suse.com/1256574",[139],[146],{"url":172,"sources":173,"tags":174},"https://bugzilla.suse.com/1256576",[139],[146],{"url":176,"sources":177,"tags":178},"https://bugzilla.suse.com/1256848",[139],[146],{"url":180,"sources":181,"tags":182},"https://bugzilla.suse.com/1259853",[139],[146],{"url":184,"sources":185,"tags":186},"https://bugzilla.suse.com/1260455",[139],[146],{"url":188,"sources":189,"tags":190},"https://bugzilla.suse.com/1260463",[139],[146],{"url":192,"sources":193,"tags":194},"https://bugzilla.suse.com/1260480",[139],[146],{"url":196,"sources":197,"tags":198},"https://bugzilla.suse.com/1260494",[139],[146],{"url":200,"sources":201,"tags":202},"https://bugzilla.suse.com/1268477",[139],[146],{"url":204,"sources":205,"tags":206},"https://bugzilla.suse.com/1268479",[139],[146],{"url":208,"sources":209,"tags":210},"https://bugzilla.suse.com/1268481",[139],[146],{"url":212,"sources":213,"tags":214},"https://bugzilla.suse.com/1268482",[139],[146],{"url":216,"sources":217,"tags":218},"https://bugzilla.suse.com/1268555",[139],[146],{"url":220,"sources":221,"tags":222},"https://bugzilla.suse.com/1268592",[139],[146],{"url":224,"sources":225,"tags":226},"https://bugzilla.suse.com/1268593",[139],[146],{"url":228,"sources":229,"tags":230},"https://bugzilla.suse.com/1268605",[139],[146],{"url":232,"sources":233,"tags":234},"https://bugzilla.suse.com/1268606",[139],[146],{"url":236,"sources":237,"tags":238},"https://bugzilla.suse.com/1268608",[139],[146],{"url":240,"sources":241,"tags":242},"https://bugzilla.suse.com/1268609",[139],[146],{"url":244,"sources":245,"tags":246},"https://bugzilla.suse.com/1268611",[139],[146],{"url":248,"sources":249,"tags":250},"https://bugzilla.suse.com/1268618",[139],[146],{"url":252,"sources":253,"tags":254},"https://bugzilla.suse.com/1269825",[139],[146],{"url":256,"sources":257,"tags":258},"https://bugzilla.suse.com/1272941",[139],[146],{"url":260,"sources":261,"tags":262},"https://bugzilla.suse.com/1272942",[139],[146],{"url":264,"sources":265,"tags":266},"https://bugzilla.suse.com/1272943",[139],[146],{"url":268,"sources":269,"tags":270},"https://bugzilla.suse.com/1272944",[139],[146],{"url":272,"sources":273,"tags":274},"https://bugzilla.suse.com/1272945",[139],[146],{"url":276,"sources":277,"tags":278},"https://bugzilla.suse.com/1272947",[139],[146],{"url":280,"sources":281,"tags":282},"https://bugzilla.suse.com/1272948",[139],[146],{"url":284,"sources":285,"tags":286},"https://bugzilla.suse.com/1272951",[139],[146],{"url":288,"sources":289,"tags":290},"https://bugzilla.suse.com/1272958",[139],[146],{"url":292,"sources":293,"tags":294},"https://bugzilla.suse.com/1273591",[139],[146],{"url":296,"sources":297,"tags":298},"https://bugzilla.suse.com/1273593",[139],[146],{"url":300,"sources":301,"tags":302},"https://www.suse.com/security/cve/CVE-2025-22150",[139],[303],"WEB",{"url":305,"sources":306,"tags":307},"https://www.suse.com/security/cve/CVE-2025-23166",[139],[303],{"url":309,"sources":310,"tags":311},"https://www.suse.com/security/cve/CVE-2025-23167",[139],[303],{"url":313,"sources":314,"tags":315},"https://www.suse.com/security/cve/CVE-2025-55131",[139],[303],{"url":317,"sources":318,"tags":319},"https://www.suse.com/security/cve/CVE-2025-59465",[139],[303],{"url":321,"sources":322,"tags":323},"https://www.suse.com/security/cve/CVE-2025-59466",[139],[303],{"url":325,"sources":326,"tags":327},"https://www.suse.com/security/cve/CVE-2025-62408",[139],[303],{"url":329,"sources":330,"tags":331},"https://www.suse.com/security/cve/CVE-2026-11525",[139],[303],{"url":333,"sources":334,"tags":335},"https://www.suse.com/security/cve/CVE-2026-12151",[139],[303],{"url":337,"sources":338,"tags":339},"https://www.suse.com/security/cve/CVE-2026-15157",[139],[303],{"url":341,"sources":342,"tags":343},"https://www.suse.com/security/cve/CVE-2026-16728",[139],[303],{"url":345,"sources":346,"tags":347},"https://www.suse.com/security/cve/CVE-2026-16729",[139],[303],{"url":349,"sources":350,"tags":351},"https://www.suse.com/security/cve/CVE-2026-21637",[139],[303],{"url":353,"sources":354,"tags":355},"https://www.suse.com/security/cve/CVE-2026-21710",[139],[303],{"url":357,"sources":358,"tags":359},"https://www.suse.com/security/cve/CVE-2026-21713",[139],[303],{"url":361,"sources":362,"tags":363},"https://www.suse.com/security/cve/CVE-2026-21714",[139],[303],{"url":365,"sources":366,"tags":367},"https://www.suse.com/security/cve/CVE-2026-21717",[139],[303],{"url":369,"sources":370,"tags":371},"https://www.suse.com/security/cve/CVE-2026-22036",[139],[303],{"url":373,"sources":374,"tags":375},"https://www.suse.com/security/cve/CVE-2026-27135",[139],[303],{"url":377,"sources":378,"tags":379},"https://www.suse.com/security/cve/CVE-2026-48618",[139],[303],{"url":381,"sources":382,"tags":383},"https://www.suse.com/security/cve/CVE-2026-48619",[139],[303],{"url":385,"sources":386,"tags":387},"https://www.suse.com/security/cve/CVE-2026-48928",[139],[303],{"url":389,"sources":390,"tags":391},"https://www.suse.com/security/cve/CVE-2026-48930",[139],[303],{"url":393,"sources":394,"tags":395},"https://www.suse.com/security/cve/CVE-2026-48931",[139],[303],{"url":397,"sources":398,"tags":399},"https://www.suse.com/security/cve/CVE-2026-48933",[139],[303],{"url":401,"sources":402,"tags":403},"https://www.suse.com/security/cve/CVE-2026-48934",[139],[303],{"url":405,"sources":406,"tags":407},"https://www.suse.com/security/cve/CVE-2026-48935",[139],[303],{"url":409,"sources":410,"tags":411},"https://www.suse.com/security/cve/CVE-2026-48937",[139],[303],{"url":413,"sources":414,"tags":415},"https://www.suse.com/security/cve/CVE-2026-56846",[139],[303],{"url":417,"sources":418,"tags":419},"https://www.suse.com/security/cve/CVE-2026-56848",[139],[303],{"url":421,"sources":422,"tags":423},"https://www.suse.com/security/cve/CVE-2026-56850",[139],[303],{"url":425,"sources":426,"tags":427},"https://www.suse.com/security/cve/CVE-2026-58040",[139],[303],{"url":429,"sources":430,"tags":431},"https://www.suse.com/security/cve/CVE-2026-58042",[139],[303],{"url":433,"sources":434,"tags":435},"https://www.suse.com/security/cve/CVE-2026-58043",[139],[303],{"url":437,"sources":438,"tags":439},"https://www.suse.com/security/cve/CVE-2026-58044",[139],[303],{"url":441,"sources":442,"tags":443},"https://www.suse.com/security/cve/CVE-2026-58045",[139],[303],{"url":445,"sources":446,"tags":447},"https://www.suse.com/security/cve/CVE-2026-6733",[139],[303],{"url":449,"sources":450,"tags":451},"https://www.suse.com/security/cve/CVE-2026-9679",[139],[303],[],[],[],[456,469],{"ecosystem":457,"name":458,"vendor":459,"product":460,"cpe_part":9,"purl_type":461,"purl_namespace":459,"purl_name":460,"source":9,"versions":462},"SUSE Linux Enterprise","nodejs18","suse","nodejs18&distro=SUSE Linux Enterprise Server 12 SP5-LTSS","rpm",[463],{"version":464,"is_range":465,"range_type":466,"version_start":9,"version_start_type":9,"version_end":467,"version_end_type":468,"fixed_in":9},"lt18_20_8_8_44_1",true,"ecosystem","18.20.8-8.44.1","excluding",{"ecosystem":457,"name":458,"vendor":459,"product":470,"cpe_part":9,"purl_type":461,"purl_namespace":459,"purl_name":470,"source":9,"versions":471},"nodejs18&distro=SUSE Linux Enterprise Server LTSS Extended Security 12 SP5",[472],{"version":464,"is_range":465,"range_type":466,"version_start":9,"version_start_type":9,"version_end":467,"version_end_type":468,"fixed_in":9}]