-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 22 Sep 2026 19:12:18 +0200 Source: nodejs Binary: libnode-dev libnode115 libnode115-dbgsym nodejs nodejs-dbgsym Architecture: arm64 Version: 20.19.2+dfsg-1+deb13u3 Distribution: trixie-security Urgency: medium Maintainer: arm64 Build Daemon (arm-ubc-05) Changed-By: Bastien Roucariès Description: libnode-dev - evented I/O for V8 javascript (development files) libnode115 - evented I/O for V8 javascript - runtime library nodejs - evented I/O for V8 javascript - runtime executable Changes: nodejs (20.19.2+dfsg-1+deb13u3) trixie-security; urgency=medium . * Team upload * Fix CVE-2026-48617: A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48618: A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48619: A malicious HTTP/2 server can send repeated ORIGIN frames with unique origins, causing unbounded growth of the client-side originSet for the lifetime of the session. Cap the set at 128 entries; once full, new origins from ORIGIN frames are silently dropped. * Fix CVE-2026-48928: case-sensitive SNI context matching The regex constructed by server.addContext() lacked the case-insensitive flag, causing uppercase or mixed-case SNI hostnames from ClientHello to miss their intended context and fall back to the default context. This violates RFC 6066 Section 3, which states that DNS hostnames are case-insensitive. In mTLS configurations with per-tenant contexts, this allowed bypassing client certificate authorization by simply uppercasing the SNI hostname. * Fix CVE-2026-48930: A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. * Fix CVE-2026-48931: HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. * Fix CVE-2026-48933: A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. * Fix CVE-2026-48934: A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. * Fix CVE-2026-48935: A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. --allow-fs-read. * Fix CVE-2026-48937: A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. * Fix CVE-2026-56846 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. * Fix CVE-2026-56847: A flaw in Node.js Permission Model enforcement allows trace_events.createTracing().enable() Writes Trace Logs Outside --allow-fs-write. * Fix CVE-2026-56848: A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. * Fix CVE-2026-56850: A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. * Fix CVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations * Fix CVE-2026-58043! A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. * Fix CVE-2026-58040: An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). Checksums-Sha1: 80740dde379c5e2bd105174fa1b668db602970ae 538540 libnode-dev_20.19.2+dfsg-1+deb13u3_arm64.deb a1118358285efc83d48674c98330c7e2ef73bd8e 1051935384 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_arm64.deb 0d3ada63628bdc86f3349238b3993c4f77eed400 10902960 libnode115_20.19.2+dfsg-1+deb13u3_arm64.deb 0b68d76bd661a98c76fa23b7b03f258218629c94 82692 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_arm64.deb 5db99ba057a31d0fcff70c76100c5cbd3e437800 11209 nodejs_20.19.2+dfsg-1+deb13u3_arm64-buildd.buildinfo 956653f3f4f8c2d9b9456c179091ca6ab1ac8907 354892 nodejs_20.19.2+dfsg-1+deb13u3_arm64.deb Checksums-Sha256: cbcf4c7729b7044bfd2e62e952ade5dd043e9c26dfddcad6e3c36dc70fee79db 538540 libnode-dev_20.19.2+dfsg-1+deb13u3_arm64.deb 3d211d2b1c138e3ae534f7a8fc159f3f1b2ed1755e43683971113c05eb46b32c 1051935384 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_arm64.deb 5ac5229d5cb4c2b5fd4416878bea5833e5ad6ef6b01eb228d25ae1f8ca6a15ba 10902960 libnode115_20.19.2+dfsg-1+deb13u3_arm64.deb 02177d9eb84cb2fec9931bce275634de87ede558c0fbe3196754d3cce8348446 82692 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_arm64.deb bccfdd34aa003717327e4313f71cdb7e4bd91c2279496c80fea05507bbd02aad 11209 nodejs_20.19.2+dfsg-1+deb13u3_arm64-buildd.buildinfo a92077b99707d2199342a197a58f4a8aa78b213ff7e0906653c958f42da163e2 354892 nodejs_20.19.2+dfsg-1+deb13u3_arm64.deb Files: d40f1a7c3fcbd7d6cf990ef10412f7de 538540 libdevel optional libnode-dev_20.19.2+dfsg-1+deb13u3_arm64.deb ce5c0a92773084ca1dcbb04793812709 1051935384 debug optional libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_arm64.deb ecadb528913e4d84973ea7125cc70e15 10902960 libs optional libnode115_20.19.2+dfsg-1+deb13u3_arm64.deb c392fe945876f36cd2d4d968f9c0a1fd 82692 debug optional nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_arm64.deb 0770b4156ab4f15625e0125403eb82de 11209 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_arm64-buildd.buildinfo 6b4bf813b84f0a31885c7094132134d0 354892 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_arm64.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7rv+l3KtZdQea77lnwznazfjXToFAmq8MQwACgkQnwznazfj XTqTiRAA5Ch8jaFuw75gbGl4PlGBWLfARZuf5eLyPp0qVvLtZeIz28VB6K1jB6EL zXOtx5KDm/T904ZDkDLwsMMNexXIGLVCG7xwWhBw3RM6ik1ADygEwlWWcKhwXYb0 84HKngIGT7s5P2ovNansQvSGtX/zFz1DbRAGI07vsJanEnLoy1SnEUJikUDmRNCZ Gf0MYfrX/ZM67AGZVcUdfs5HYKYLYdZZD8+OqgtU1yA4iXLGUqQQT0kRj2cxerw3 dZi0jov8RzXK/qGd5Q5Rw0G/2PtZNcfqRnJFxFGyg7YHiaxyKjgi8AbO2pvXYt7K s6/PAtt27yA080xZXKgyQi47+zIz+TYZaH5kK7CutAMnb2t2r1vL/67IkD0rl0Vl 7RM7HgH02HpCyLBwzN6GRmcNUz5QvCJR0livqixjiJHrlKNqZzv8Wv87dRd2JeAH HLZ2o32hpzBaJIa1DSIS5r1ik2p/HUbNokyzHM4fNUw+UPjlXUxxhGGGBwb10IGn UeLixcX22KVSgUFnwOAfvkSPxvgs8cHzkp36x28dmzM6GEorjq4mNUxLB4S/fisb yoN1EvPaLBDYamG1n/uzzqWsIZFe49vbaX+QSL3Wy4Jw0dP09yW/dN6hmTH7sQYL S92tgJs8cK8jb/UXhwEQ1FTJWPxYzeuqz2fdbO0+OoIqHGtDG9c= =IRUZ -----END PGP SIGNATURE-----