-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 22 Sep 2026 19:12:18 +0200 Source: nodejs Binary: libnode-dev libnode115 libnode115-dbgsym nodejs nodejs-dbgsym Architecture: armhf Version: 20.19.2+dfsg-1+deb13u3 Distribution: trixie-security Urgency: medium Maintainer: armhf Build Daemon (arm-ubc-05) Changed-By: Bastien Roucariès Description: libnode-dev - evented I/O for V8 javascript (development files) libnode115 - evented I/O for V8 javascript - runtime library nodejs - evented I/O for V8 javascript - runtime executable Changes: nodejs (20.19.2+dfsg-1+deb13u3) trixie-security; urgency=medium . * Team upload * Fix CVE-2026-48617: A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48618: A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48619: A malicious HTTP/2 server can send repeated ORIGIN frames with unique origins, causing unbounded growth of the client-side originSet for the lifetime of the session. Cap the set at 128 entries; once full, new origins from ORIGIN frames are silently dropped. * Fix CVE-2026-48928: case-sensitive SNI context matching The regex constructed by server.addContext() lacked the case-insensitive flag, causing uppercase or mixed-case SNI hostnames from ClientHello to miss their intended context and fall back to the default context. This violates RFC 6066 Section 3, which states that DNS hostnames are case-insensitive. In mTLS configurations with per-tenant contexts, this allowed bypassing client certificate authorization by simply uppercasing the SNI hostname. * Fix CVE-2026-48930: A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. * Fix CVE-2026-48931: HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. * Fix CVE-2026-48933: A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. * Fix CVE-2026-48934: A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. * Fix CVE-2026-48935: A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. --allow-fs-read. * Fix CVE-2026-48937: A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. * Fix CVE-2026-56846 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. * Fix CVE-2026-56847: A flaw in Node.js Permission Model enforcement allows trace_events.createTracing().enable() Writes Trace Logs Outside --allow-fs-write. * Fix CVE-2026-56848: A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. * Fix CVE-2026-56850: A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. * Fix CVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations * Fix CVE-2026-58043! A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. * Fix CVE-2026-58040: An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). Checksums-Sha1: 4de722bea5eba46c560004e51872832af5d6d4da 538492 libnode-dev_20.19.2+dfsg-1+deb13u3_armhf.deb cf6cc0594c4567e4a4833beb65b559abc23c675c 39163404 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_armhf.deb 442e3462b00bb6bd9a2b1886d3371bd49efee76f 10225928 libnode115_20.19.2+dfsg-1+deb13u3_armhf.deb b6678c3f46f86053e2547b5893012e0fbae150ab 3252 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_armhf.deb 844cc04c6b420ca06a7f847a3ea4bc466ea5af93 11082 nodejs_20.19.2+dfsg-1+deb13u3_armhf-buildd.buildinfo 4881e1fda2ce3efa0a93c493247228320148c72d 354820 nodejs_20.19.2+dfsg-1+deb13u3_armhf.deb Checksums-Sha256: 40839ec90663ca0d9818bf65276bb7ac9643e7bd7978e15c7ad6904c9ec3080d 538492 libnode-dev_20.19.2+dfsg-1+deb13u3_armhf.deb 100ac21787bd8161dea32f0ba65c4da351e81b9553cb0f56ae106aa61ba9eeff 39163404 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_armhf.deb 06b8962d55294be02b9789e97e896d4b537b2621039b55f5cb06c03921ae6546 10225928 libnode115_20.19.2+dfsg-1+deb13u3_armhf.deb 2ed2f58c3f505fd09c6167d1c86783c576e5fbbbb3c94dec67f6a8cc0aa118a9 3252 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_armhf.deb 7dd2962626b927c7d6adadd11131ff49d84e451e48d3e8784abab947b19e8508 11082 nodejs_20.19.2+dfsg-1+deb13u3_armhf-buildd.buildinfo 0cd04e80d3d1dbfe6c18efe5618a7f795e1612d895fc2e0102d73d94ebacfac7 354820 nodejs_20.19.2+dfsg-1+deb13u3_armhf.deb Files: 2b20335920d0fd8eef4be443c66bde20 538492 libdevel optional libnode-dev_20.19.2+dfsg-1+deb13u3_armhf.deb a84118f11788cdbea422ded7d8426953 39163404 debug optional libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_armhf.deb a560c0fb8a971f8377a2d8e1dee176f9 10225928 libs optional libnode115_20.19.2+dfsg-1+deb13u3_armhf.deb f15da59f2d79a63ba3fc816fd39d3488 3252 debug optional nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_armhf.deb b3e89cecd040bbc53bc6878aee765922 11082 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_armhf-buildd.buildinfo 35a78c2c51e1f29f77c9b254d3b67fd7 354820 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_armhf.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7rv+l3KtZdQea77lnwznazfjXToFAmqzSDEACgkQnwznazfj XTpACQ/+PTeJEzfy5zffgEJCF+o/Y+fukQDNUXuJ60dNQJWs39iDspvH2SeSvTEN 2PcT9U3Gi7SHfLeunmfTcSZy/jxbCeasDhqcn2irtuYUlyJAklTXtRJ8Bsao3Yqr mAuh0vME9Xxi3riYm/txP0srcOQyLrmJwv4iB6/bOKOfVAAiCwKYXz15hEtc45kK J2p/4xMQZ/8fviKoE4wcJm4Fd/8n188qq42NmxM8W+fl1mvxtzvr1kQdGdSVKDKH aTaXWUGTUJrBwVh5/Oacl8gz8t2weIcRUlm74Xt33iyR7ceoYHcX9rJMEGpzCp+b RVcGugv6zfxfb6tTpSsLGxDG4EFCZWzu4ImZkeBKkXvfhTFSR5vWDFgGhmzsWcqP Ye/vJvW7wkRqRUWqKwKthz/TInF4hFeprDXPtLOCE7mfEwmoQdWLXNeY1gHOYRGo iyXqJkiD6PcxQU6GT2xO2Ha830+2QLPcU1TrBoUhvVSbGox3pKlGyGPPfwizGbZU KyijMgB3hYn7jzPnajG+ljZGZrxYi147SeN/EkiOicqD7+y5BGDgYede65SGXO3x D11+PirGmf/jIIOI77rz45mJk8zwbYVDa4mlSXkEb+NF930o4lFlCS7MUr4Xh/w1 vet8zDd7wJi3wg68WUM2xWMZqXA4waYZIt6OBSSFHAKdGwQSv0I= =OP/K -----END PGP SIGNATURE-----