-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 22 Sep 2026 19:12:18 +0200 Source: nodejs Binary: libnode-dev libnode115 libnode115-dbgsym nodejs nodejs-dbgsym Architecture: armel Version: 20.19.2+dfsg-1+deb13u3 Distribution: trixie-security Urgency: medium Maintainer: armel Build Daemon (arm-conova-02) Changed-By: Bastien Roucariès Description: libnode-dev - evented I/O for V8 javascript (development files) libnode115 - evented I/O for V8 javascript - runtime library nodejs - evented I/O for V8 javascript - runtime executable Changes: nodejs (20.19.2+dfsg-1+deb13u3) trixie-security; urgency=medium . * Team upload * Fix CVE-2026-48617: A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48618: A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48619: A malicious HTTP/2 server can send repeated ORIGIN frames with unique origins, causing unbounded growth of the client-side originSet for the lifetime of the session. Cap the set at 128 entries; once full, new origins from ORIGIN frames are silently dropped. * Fix CVE-2026-48928: case-sensitive SNI context matching The regex constructed by server.addContext() lacked the case-insensitive flag, causing uppercase or mixed-case SNI hostnames from ClientHello to miss their intended context and fall back to the default context. This violates RFC 6066 Section 3, which states that DNS hostnames are case-insensitive. In mTLS configurations with per-tenant contexts, this allowed bypassing client certificate authorization by simply uppercasing the SNI hostname. * Fix CVE-2026-48930: A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. * Fix CVE-2026-48931: HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. * Fix CVE-2026-48933: A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. * Fix CVE-2026-48934: A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. * Fix CVE-2026-48935: A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. --allow-fs-read. * Fix CVE-2026-48937: A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. * Fix CVE-2026-56846 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. * Fix CVE-2026-56847: A flaw in Node.js Permission Model enforcement allows trace_events.createTracing().enable() Writes Trace Logs Outside --allow-fs-write. * Fix CVE-2026-56848: A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. * Fix CVE-2026-56850: A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. * Fix CVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations * Fix CVE-2026-58043! A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. * Fix CVE-2026-58040: An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). Checksums-Sha1: a149ddcfce6e11175a52b4c17288ceda5dac4d92 538572 libnode-dev_20.19.2+dfsg-1+deb13u3_armel.deb 2f8f14a365fd12a2d7286904aa09ff40f88f1be0 39094216 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_armel.deb 7d427168a3b227d8ae5092212f2b4cfddd0cfb44 10184052 libnode115_20.19.2+dfsg-1+deb13u3_armel.deb 657f86a67d8bf6898526d2bf6b221bc2d65e74b9 3264 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_armel.deb 4901c89df71797d5338753996916e5d3363315f4 11136 nodejs_20.19.2+dfsg-1+deb13u3_armel-buildd.buildinfo d060125aafd608741ba31780e4cae0432ff7c26e 354800 nodejs_20.19.2+dfsg-1+deb13u3_armel.deb Checksums-Sha256: 8563f9affae66163c5f34de386f9b637b066e2a6c0ca1a1ea7979d2259366fd8 538572 libnode-dev_20.19.2+dfsg-1+deb13u3_armel.deb 43b81a47548b72c5f330500f224aac1dfb3af4eab3972580affdb82fc2d1f0a2 39094216 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_armel.deb 56b7bc897d41fdf83e928e45d04f7f1e558bedbfa5f2519d5695ef6007f3b444 10184052 libnode115_20.19.2+dfsg-1+deb13u3_armel.deb f3b9ac771782518ac5d005238a4447fe52fa1dc4df9b3391ca82d8fb5d70dec0 3264 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_armel.deb a739238f9be73a4ff5c473ad062314d4113fd2beb3d5f4c1f1d1755b66d372d4 11136 nodejs_20.19.2+dfsg-1+deb13u3_armel-buildd.buildinfo 13917c9fe3e7a92cd92787df97af89cda284e3cf4681e45a28a180deb53dfce3 354800 nodejs_20.19.2+dfsg-1+deb13u3_armel.deb Files: 82d4d75b4eefb40acb7403eb4d517f0b 538572 libdevel optional libnode-dev_20.19.2+dfsg-1+deb13u3_armel.deb fde9a6a6cf41260776ffb35a03b43b28 39094216 debug optional libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_armel.deb 7ba47285fcdcb683cd020b4464331bcb 10184052 libs optional libnode115_20.19.2+dfsg-1+deb13u3_armel.deb 52d262fa1886328e332e26c23d981d36 3264 debug optional nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_armel.deb c9ef54f6445e7fc5887dab06d791a5cc 11136 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_armel-buildd.buildinfo ff8d7a197941f299a5d2f368031ef7e1 354800 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_armel.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEa5s+5E+WDkV2pQjwIyDMsRzdi8EFAmqzVyQACgkQIyDMsRzd i8GDSw/9HHAUcF3+n/Doiip8vx3KzRRs21g8x9U63vOrooEq5u6NQ3kUNSSdhg+b eoJC5PVxQIi9j5XlZjGi7laNxXh3waLYyYmcuQhOjd10TUKPaLSNqEGTMld/f+St 6scEtpa7E/Xo/MSCVASmZ+h6vRKV1cG15DKscsPrQsJo25InWmlz1aDXJc3cTTxY d8I9M0+fbQ0QNtWv23hE9zy3UVJrL7tXjmgXBoGRmmMOjcj4tc5yGMyhX7isktgZ w2CovRLFPakr3CHElp6hK1dvKoDyjruoCILYIl21X/TZW1M1iGyTxHojiP3vN/4h 0ldCMCCfE4uBwKGB+3pJNRUqtrTvnGcHmGfuAd5zz7qWTy+AIhO4M8dx0KcgNZnW 2kxGcYU9oDPxhhhlYFGlN8AmC8zZ0Wm5QXVAy5HDTXZCo4xkLUf1rWkha+LFvaTD 84uS9irnUsQdtm4JNWWbpIHKb3+BMIH+MlENPyHLrW9KjC2IPj/9U4ElkLtBTRAo 16krNp7bFStCubvsJcp01cGOcuz3kstqnZfqovfVDhyi/gRHWLmlwmsl1d/INzvQ 7eCXQSRUUrA5tSyZuGi6dZkCK7/gPt0AdnKQhy7dQbBC59xr5Xkj8BAVjJWdyi9/ XE+ALXJXp4PRWBRUWGK7pi5NSYYAQ5g70KHZaZFihT2txjN8Tuw= =9VpM -----END PGP SIGNATURE-----