-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 22 Sep 2026 19:12:18 +0200 Source: nodejs Binary: nodejs-doc Architecture: all Version: 20.19.2+dfsg-1+deb13u3 Distribution: trixie-security Urgency: medium Maintainer: all Build Daemon (x86-grnet-02) Changed-By: Bastien Roucariès Description: nodejs-doc - API documentation for Node.js, the javascript platform Changes: nodejs (20.19.2+dfsg-1+deb13u3) trixie-security; urgency=medium . * Team upload * Fix CVE-2026-48617: A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48618: A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48619: A malicious HTTP/2 server can send repeated ORIGIN frames with unique origins, causing unbounded growth of the client-side originSet for the lifetime of the session. Cap the set at 128 entries; once full, new origins from ORIGIN frames are silently dropped. * Fix CVE-2026-48928: case-sensitive SNI context matching The regex constructed by server.addContext() lacked the case-insensitive flag, causing uppercase or mixed-case SNI hostnames from ClientHello to miss their intended context and fall back to the default context. This violates RFC 6066 Section 3, which states that DNS hostnames are case-insensitive. In mTLS configurations with per-tenant contexts, this allowed bypassing client certificate authorization by simply uppercasing the SNI hostname. * Fix CVE-2026-48930: A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. * Fix CVE-2026-48931: HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. * Fix CVE-2026-48933: A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. * Fix CVE-2026-48934: A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. * Fix CVE-2026-48935: A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. --allow-fs-read. * Fix CVE-2026-48937: A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. * Fix CVE-2026-56846 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. * Fix CVE-2026-56847: A flaw in Node.js Permission Model enforcement allows trace_events.createTracing().enable() Writes Trace Logs Outside --allow-fs-write. * Fix CVE-2026-56848: A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. * Fix CVE-2026-56850: A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. * Fix CVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations * Fix CVE-2026-58043! A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. * Fix CVE-2026-58040: An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). Checksums-Sha1: a71c8fc881301163fc009b515d0b1e7855ac19ea 6087656 nodejs-doc_20.19.2+dfsg-1+deb13u3_all.deb 4e7fdcab812cc5158c0690c25d4281cf62e1ea4f 10215 nodejs_20.19.2+dfsg-1+deb13u3_all-buildd.buildinfo Checksums-Sha256: 330defda9cac8dde1a26d4bcba07f9789a4d65ba080fc9e1bdfb9b247010870e 6087656 nodejs-doc_20.19.2+dfsg-1+deb13u3_all.deb 702ddca6ffc88f1fa5523ed2454fc94a01ab821e8e8fec05e7cf0cd35217a3a0 10215 nodejs_20.19.2+dfsg-1+deb13u3_all-buildd.buildinfo Files: f80a319c257e091b33d7723c5757c46a 6087656 doc optional nodejs-doc_20.19.2+dfsg-1+deb13u3_all.deb e5b294f12c4857ba1253380127274be0 10215 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_all-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE81O8NL+3kjBAqEvLmgPNRvTf/zcFAmqy95IACgkQmgPNRvTf /zdCow/+NyYWZ2p5R206jNudV3MuosAAC97dPnzZ4rp3UOCN1RUk40N5a0unYZHO vhvH7v+xuQIrhoz3icn/8hBBRLtw8lSJefTIOyZtEBvqBLCPf2BeBZ6eI+DWaw2l 0wcPwipwch/jvoJzzbeE7fp0t3TY2TWdZ4NOBKaQHjGpUpG5t5RD6L/8FqxdnSrv V0xW936ZWGLmh/lmYHnbNUfC2r9Eo5aiVo4uvi3k14oemIW4KTmiyoF8RQbTTJmk OpnDlcV6VJJXkCuJKzmtxlBdkww699nGUFLbAypRMmjrtGQElVUggJb63Rs3RTJr atxiE1KTZl9fHdJ4qfWT9yxyizwlIBWnbpxmOGZXHogzIXnKGPxKSRPXKc7FMbCm UU5QnkdHj1SuBdwNlfCbd2Ubo0yb4OL0GCa5lvgJ9jNMZXsQo6ctzJ/EIcUhSmKa DK2v1DbFxT1R4hT6JCu/kjhXl8VmQyEv7IrihP9ZbIxGcrtcPZnL/TIYFdHoM5hC OGD9ZaZMZZM1NmcdeFfDCpaL3ipwJSpghEoQqfQ26Vft2pJKaZtz1qXDRIul3Mwv EjnHpw1jr3uTdbb6+Ugfh8KcJG+pnHHod8BbjCYYlHuSzcF8luiYQ467Y6Di1Doq H/1InVF0FuFG+zFbHc4ur7bp7f+FUBuApnjZy1hCpbTM0ohdZRA= =5BkU -----END PGP SIGNATURE-----