-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 22 Sep 2026 19:12:18 +0200 Source: nodejs Binary: libnode-dev libnode115 libnode115-dbgsym nodejs nodejs-dbgsym Architecture: riscv64 Version: 20.19.2+dfsg-1+deb13u3 Distribution: trixie-security Urgency: medium Maintainer: riscv64 Build Daemon (rv-osuosl-01) Changed-By: Bastien Roucariès Description: libnode-dev - evented I/O for V8 javascript (development files) libnode115 - evented I/O for V8 javascript - runtime library nodejs - evented I/O for V8 javascript - runtime executable Changes: nodejs (20.19.2+dfsg-1+deb13u3) trixie-security; urgency=medium . * Team upload * Fix CVE-2026-48617: A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48618: A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48619: A malicious HTTP/2 server can send repeated ORIGIN frames with unique origins, causing unbounded growth of the client-side originSet for the lifetime of the session. Cap the set at 128 entries; once full, new origins from ORIGIN frames are silently dropped. * Fix CVE-2026-48928: case-sensitive SNI context matching The regex constructed by server.addContext() lacked the case-insensitive flag, causing uppercase or mixed-case SNI hostnames from ClientHello to miss their intended context and fall back to the default context. This violates RFC 6066 Section 3, which states that DNS hostnames are case-insensitive. In mTLS configurations with per-tenant contexts, this allowed bypassing client certificate authorization by simply uppercasing the SNI hostname. * Fix CVE-2026-48930: A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. * Fix CVE-2026-48931: HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. * Fix CVE-2026-48933: A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. * Fix CVE-2026-48934: A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. * Fix CVE-2026-48935: A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. --allow-fs-read. * Fix CVE-2026-48937: A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. * Fix CVE-2026-56846 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. * Fix CVE-2026-56847: A flaw in Node.js Permission Model enforcement allows trace_events.createTracing().enable() Writes Trace Logs Outside --allow-fs-write. * Fix CVE-2026-56848: A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. * Fix CVE-2026-56850: A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. * Fix CVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations * Fix CVE-2026-58043! A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. * Fix CVE-2026-58040: An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). Checksums-Sha1: 520d4519d8ca1e5b2f1b094c7b2f4581448b7d28 538468 libnode-dev_20.19.2+dfsg-1+deb13u3_riscv64.deb 03157e75e523657eb3e962140731159457bc1412 951427772 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_riscv64.deb 2574681dcf6a7d17741f64d3b683c3913c3b9b30 12468348 libnode115_20.19.2+dfsg-1+deb13u3_riscv64.deb a479fd7b67025bd6666cbe1dc2a037a523adc56b 82884 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_riscv64.deb 29e13cfd20c2465e8a2f2b9a98025e7cb529eb29 11184 nodejs_20.19.2+dfsg-1+deb13u3_riscv64-buildd.buildinfo 54357002c63cf291b3bef09a77e733d14eb57166 354764 nodejs_20.19.2+dfsg-1+deb13u3_riscv64.deb Checksums-Sha256: 3fffbf4b9f300663f52568f7ff3dcf7963c6efa180092a7ebebbd242bf5d027f 538468 libnode-dev_20.19.2+dfsg-1+deb13u3_riscv64.deb 46ec204972e670756318cbd0776c54ba7b4bf6a4e5cc07a4e484e7320a90ecaa 951427772 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_riscv64.deb 87cec8daf1dc27e9e8a8a146fc9eb81f045a66f7a1f5ab469c6732ffa8ebb9cf 12468348 libnode115_20.19.2+dfsg-1+deb13u3_riscv64.deb f725635f98a86eb2625ca7120506017ad6ed72817f5ca147b185c7b6c9b28dcd 82884 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_riscv64.deb 61aaeb9bcf2e0daabb8dbe97c7e66a6d3bfc80b4ce55b3527dd6d60cf314820e 11184 nodejs_20.19.2+dfsg-1+deb13u3_riscv64-buildd.buildinfo c83ee65b585da6d9a0ac0113c246fa6544072164e85dd2f4fd76a94f8c865a7c 354764 nodejs_20.19.2+dfsg-1+deb13u3_riscv64.deb Files: d1ccb9571b11381a1ffcdd8686a71a46 538468 libdevel optional libnode-dev_20.19.2+dfsg-1+deb13u3_riscv64.deb e7f7388fe874196fa6273d16c887015b 951427772 debug optional libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_riscv64.deb 90fca841048c67cd8d5020fbc35956ad 12468348 libs optional libnode115_20.19.2+dfsg-1+deb13u3_riscv64.deb 320023ab815f9beb703352829a398a50 82884 debug optional nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_riscv64.deb 80abd123698929345ed735b8feba4d39 11184 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_riscv64-buildd.buildinfo 0a1338307972086a5d778ed5276f8f60 354764 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_riscv64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE3smN1vgomTkXJcrkIhSPlPtgqxkFAmq1J5gACgkQIhSPlPtg qxlntBAApcsHAL0IStcFugFe+MaQfx0NZ6OCVw/QZ8rNrKNYC6gU7T0k4b1NI/w5 MgGFOMsB8u8Br06nBi8o4a54bjzHj+C/Cf5e13xJunzyDjqKVK0i9fKvGd0WgmHB HSxq0FlWd+PYgCAoOhcD64TGcNSIhumi5pKHnWh3ArXp5afNA689iE8k0TCNhEAY klQHBn3mMIUZKcDMMIfWMZ3g7UZcmDQYepZBDHFdAchpKlNSSu+6wnoZHokpC+cQ OG1FVL/AVsakQBancZ6Mt1W5Hzkk7lkl/QcCW8Xt4YD74qtHqsPq+Nv5TSO+LAUr /GqVZriU/rB0DiWWk5GwKVR5+xnryYDUA9CGQcHZeyd7ZGTvlvxGOkEGTuHC02Dp uJgPZjP+GSqnQLJMieOQ7tXmlYPZB4rGl08TzhsJrOVuE+P9+QRtCuTiOPAlwy7/ AxcMAq7BxkuEL5OZYvSyTwQ3H6wJs2NIh8WmkGhKJGRWVOSNydld7oXNlzv19uLl OvZpYhCMHPzgTXQv5hUF45zMeU9HVsnGcrzZMx08A30aZfCe0dcw1WS8jqri669p eqUOJ5i5pxnHrICxIBfpz6pRbIk210DVZ/fmpjc15i1CBEzhxUwX1QkzsMaNzRqo YfxbUAEjqkuLHE3mhkYvo2Q3r7c6qUXjmQu1klDnKIlzqt3UdZY= =Aq9i -----END PGP SIGNATURE-----