gpp_maybe Security update for nodejs24
SUSE-SLE-Module-Web-Scripting-15-SP7-2026-3520


This update for nodejs24 fixes the following issues: Update to 24.18.1. - CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust- boundary checks (bsc#1272882). - CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941). - CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949). - CVE-2026-56848: HTTP/2 re-entrant send can cause heap use-after-free (bsc#1272942). - CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944). - CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950). - CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945). - CVE-2026-58041: `node:sqlite` `SQLTagStore` iterator replay can re-execute writes (bsc#1272946). - CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many A records (bsc#1272947). - CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943). - CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951). - CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948). Other updates and bugfixes: - Version 24.18.0: * fix: severe regression in security update 24.17 of nodejs24 (bsc#1269825) * doc: update blockList stability status to release candidate * fs: support caller-supplied readFile() buffers * http: close pre-request sockets in closeIdleConnections * loader: implement package maps * net: support TCP_KEEPINTVL and TCP_KEEPCNT in setKeepAlive * tls: add certificateCompression option * vfs: dispatch node:fs/promises to mounted VFS instances * vfs: add minimal node:vfs subsystem


cloud_download Downloads

Web and Scripting Module 15.7 s390x
  • Packages
    nodejs24
    Evented I/O for V8 JavaScript
    24.18.1-150700.15.16.1 lock rpm lock src
    nodejs24-devel
    Development headers for NodeJS 24.x
    24.18.1-150700.15.16.1 lock rpm
    nodejs24-docs
    Node.js API documentation
    24.18.1-150700.15.16.1 lock rpm
    npm24
    Package manager for Node.js
    24.18.1-150700.15.16.1 lock rpm
Web and Scripting Module 15.7 aarch64
  • Packages
    nodejs24
    Evented I/O for V8 JavaScript
    24.18.1-150700.15.16.1 lock rpm lock src
    nodejs24-devel
    Development headers for NodeJS 24.x
    24.18.1-150700.15.16.1 lock rpm
    nodejs24-docs
    Node.js API documentation
    24.18.1-150700.15.16.1 lock rpm
    npm24
    Package manager for Node.js
    24.18.1-150700.15.16.1 lock rpm
Web and Scripting Module 15.7 ppc64le
  • Packages
    nodejs24
    Evented I/O for V8 JavaScript
    24.18.1-150700.15.16.1 lock rpm lock src
    nodejs24-devel
    Development headers for NodeJS 24.x
    24.18.1-150700.15.16.1 lock rpm
    nodejs24-docs
    Node.js API documentation
    24.18.1-150700.15.16.1 lock rpm
    npm24
    Package manager for Node.js
    24.18.1-150700.15.16.1 lock rpm
Web and Scripting Module 15.7 x86_64
  • Packages
    nodejs24
    Evented I/O for V8 JavaScript
    24.18.1-150700.15.16.1 lock rpm lock src
    nodejs24-devel
    Development headers for NodeJS 24.x
    24.18.1-150700.15.16.1 lock rpm
    nodejs24-docs
    Node.js API documentation
    24.18.1-150700.15.16.1 lock rpm
    npm24
    Package manager for Node.js
    24.18.1-150700.15.16.1 lock rpm