gpp_maybe
Security update for nodejs24
SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3520
This update for nodejs24 fixes the following issues: Update to 24.18.1. - CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust- boundary checks (bsc#1272882). - CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941). - CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949). - CVE-2026-56848: HTTP/2 re-entrant send can cause heap use-after-free (bsc#1272942). - CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944). - CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950). - CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945). - CVE-2026-58041: `node:sqlite` `SQLTagStore` iterator replay can re-execute writes (bsc#1272946). - CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many A records (bsc#1272947). - CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943). - CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951). - CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948). Other updates and bugfixes: - Version 24.18.0: * fix: severe regression in security update 24.17 of nodejs24 (bsc#1269825) * doc: update blockList stability status to release candidate * fs: support caller-supplied readFile() buffers * http: close pre-request sockets in closeIdleConnections * loader: implement package maps * net: support TCP_KEEPINTVL and TCP_KEEPCNT in setKeepAlive * tls: add certificateCompression option * vfs: dispatch node:fs/promises to mounted VFS instances * vfs: add minimal node:vfs subsystem
-
Release DateAug 6 2026
-
ReferencesBugzilla: 1268097, 1269825, 1272882, 1272941, 1272942, 1272943, 1272944, 1272945, 1272946, 1272947, 1272948, 1272949, 1272950, 1272951
CVEs: CVE-2026-54272, CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-56850, CVE-2026-58039, CVE-2026-58040, CVE-2026-58041, CVE-2026-58042, CVE-2026-58043, CVE-2026-58044, CVE-2026-58045 -
Typesecurity
-
Severityimportant
cloud_download Downloads
Web and Scripting Module 15.7 s390x
-
Packagesnodejs24
Evented I/O for V8 JavaScriptnodejs24-devel24.18.1-150700.15.16.1 lock rpm lock src
Development headers for NodeJS 24.xnodejs24-docs24.18.1-150700.15.16.1 lock rpm
Node.js API documentationnpm2424.18.1-150700.15.16.1 lock rpm
Package manager for Node.js24.18.1-150700.15.16.1 lock rpm
Web and Scripting Module 15.7 aarch64
-
Packagesnodejs24
Evented I/O for V8 JavaScriptnodejs24-devel24.18.1-150700.15.16.1 lock rpm lock src
Development headers for NodeJS 24.xnodejs24-docs24.18.1-150700.15.16.1 lock rpm
Node.js API documentationnpm2424.18.1-150700.15.16.1 lock rpm
Package manager for Node.js24.18.1-150700.15.16.1 lock rpm
Web and Scripting Module 15.7 ppc64le
-
Packagesnodejs24
Evented I/O for V8 JavaScriptnodejs24-devel24.18.1-150700.15.16.1 lock rpm lock src
Development headers for NodeJS 24.xnodejs24-docs24.18.1-150700.15.16.1 lock rpm
Node.js API documentationnpm2424.18.1-150700.15.16.1 lock rpm
Package manager for Node.js24.18.1-150700.15.16.1 lock rpm
Web and Scripting Module 15.7 x86_64
-
Packagesnodejs24
Evented I/O for V8 JavaScriptnodejs24-devel24.18.1-150700.15.16.1 lock rpm lock src
Development headers for NodeJS 24.xnodejs24-docs24.18.1-150700.15.16.1 lock rpm
Node.js API documentationnpm2424.18.1-150700.15.16.1 lock rpm
Package manager for Node.js24.18.1-150700.15.16.1 lock rpm