-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Tue, 22 Sep 2026 19:12:18 +0200 Source: nodejs Binary: libnode-dev libnode115 libnode115-dbgsym nodejs nodejs-dbgsym Architecture: ppc64el Version: 20.19.2+dfsg-1+deb13u3 Distribution: trixie-security Urgency: medium Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Bastien Roucariès Description: libnode-dev - evented I/O for V8 javascript (development files) libnode115 - evented I/O for V8 javascript - runtime library nodejs - evented I/O for V8 javascript - runtime executable Changes: nodejs (20.19.2+dfsg-1+deb13u3) trixie-security; urgency=medium . * Team upload * Fix CVE-2026-48617: A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48618: A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. * Fix CVE-2026-48619: A malicious HTTP/2 server can send repeated ORIGIN frames with unique origins, causing unbounded growth of the client-side originSet for the lifetime of the session. Cap the set at 128 entries; once full, new origins from ORIGIN frames are silently dropped. * Fix CVE-2026-48928: case-sensitive SNI context matching The regex constructed by server.addContext() lacked the case-insensitive flag, causing uppercase or mixed-case SNI hostnames from ClientHello to miss their intended context and fall back to the default context. This violates RFC 6066 Section 3, which states that DNS hostnames are case-insensitive. In mTLS configurations with per-tenant contexts, this allowed bypassing client certificate authorization by simply uppercasing the SNI hostname. * Fix CVE-2026-48930: A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. * Fix CVE-2026-48931: HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. * Fix CVE-2026-48933: A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. * Fix CVE-2026-48934: A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. * Fix CVE-2026-48935: A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. --allow-fs-read. * Fix CVE-2026-48937: A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. * Fix CVE-2026-56846 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. * Fix CVE-2026-56847: A flaw in Node.js Permission Model enforcement allows trace_events.createTracing().enable() Writes Trace Logs Outside --allow-fs-write. * Fix CVE-2026-56848: A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. * Fix CVE-2026-56850: A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) client identities to be reused across requests configured with different client certificates. * Fix CVE-2026-58039: A flaw in Node.js Permission Model enforcement allows process.report writes (and overwrites) files outside --allow-fs-write paths. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations * Fix CVE-2026-58043! A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. * Fix CVE-2026-58040: An incomplete fix has been identified in Node.js: HTTPS Agent TLS session reuse skips hostname verification across identity policies (incomplete fix of CVE-2026-48934). Checksums-Sha1: 0aae830aaa578f1043e10569b6a3108151bff87d 538492 libnode-dev_20.19.2+dfsg-1+deb13u3_ppc64el.deb 9c5f40390582ffcf3dc0bfc31d18ff445ed9dcf3 1038673600 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_ppc64el.deb 5a697eb9b9c5a13e92b4c4026d0f11960f9a031a 12334004 libnode115_20.19.2+dfsg-1+deb13u3_ppc64el.deb 6e4dd897a25eec74d3455c0eb50fa3e12ee3bb86 82664 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_ppc64el.deb 0ff9fcfa24bc385ab57f7afd37607790cd1251eb 11242 nodejs_20.19.2+dfsg-1+deb13u3_ppc64el-buildd.buildinfo 0e57cf87d7b3cba2de42c9b5422bd4b601e3a8e3 354884 nodejs_20.19.2+dfsg-1+deb13u3_ppc64el.deb Checksums-Sha256: 1ff41cccdabe4b136561a1f3f8a55565160991e83722523d3df5e05932acc218 538492 libnode-dev_20.19.2+dfsg-1+deb13u3_ppc64el.deb 8b85f7263b231e0c7923eb0a6e488fa9296415a3cd695be0cc96f4e0476bff0e 1038673600 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_ppc64el.deb 91d08dd067bbe8df26b3ac8bb6a9f6d2164274bb91a03398930fde857156cd8f 12334004 libnode115_20.19.2+dfsg-1+deb13u3_ppc64el.deb c035e12e4c44f02c281112e4c4991a794ce9e36f2e15d1e085af57020764a5e5 82664 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_ppc64el.deb 8019a10914af4c52f708e7ab6330edf859e3873cf22d9808d980fe5384732efc 11242 nodejs_20.19.2+dfsg-1+deb13u3_ppc64el-buildd.buildinfo 7fa19d013cafd59a2c44996431bf149b7621d24f11da10803f45d29a4298f46e 354884 nodejs_20.19.2+dfsg-1+deb13u3_ppc64el.deb Files: 00e4a2e34de7b63defa7397f3a369c81 538492 libdevel optional libnode-dev_20.19.2+dfsg-1+deb13u3_ppc64el.deb 5a866a2f60ffcc5d6b5533e670c080aa 1038673600 debug optional libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_ppc64el.deb 313df3e43768a64c288c99f4d37cd592 12334004 libs optional libnode115_20.19.2+dfsg-1+deb13u3_ppc64el.deb 0c133f2f29df54db1d425b6e1f334fb7 82664 debug optional nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_ppc64el.deb ce11f765b6a69063e9cfdf69bab70baa 11242 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_ppc64el-buildd.buildinfo 851913ae4f12afbcbbc6202e6a8b1214 354884 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_ppc64el.deb -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEySUEQfg5pZeb/U372FRWNm40e2YFAmqzCdwACgkQ2FRWNm40 e2Zc5RAAgrNngrwlZmAxtMPeN6hK4VD3KonOMt/V0zIrtIKNlAB8ZpiaMVAAJQko gLhHGEmUhr+2PR3w9DFMxAIOfW9wJXmSC4lBT1DNfbEquiGrfKgpP10WXfSZp5zc 8sCgD/1q2RtHp22Xjoi1lZ+SQnDPDH9rs1B/kszStYjJoUJvOVM7T6IGphHkxrai Q+tgk5ATMXgCy7oTSbNErR63JGkBZ9PicZe5ocCrustD56mqpyyaPqCxyGipA3Zm v0/KH+/zviu/JpNvDu21MxKY3S9hZIB8mOjQJFNVOHWOGuL2NwOlZElv6TdOs9bt CSkpQZyolPBPrX0Sig5uzIpJjgLh60voukJH5W7skrPXB/g5IW+j0rozXpnGW9FY 9LXBU67XvX7SqIVNnovOc/WWa7tu9zSzZiQUT18sMkb1/4oapJ64L7q/gQOHG/OE RKi8sAw9oAOv5kRYXz6q9BMSEiFBEy8Fo2ivKMRFMRBDWHtFTtyPuqfG18YOGPPc +QkTOloS6q+hOh1f/NQxPRsY/vMobrVNgqTeGur2RzP/ugbB/PGYLiLK2SDUNf0A NCJPFdGPOlm69wICeiT1fMjD1AgPdsbk4oTE9yB+7lgFEiYCYcZVifPN6/72Kxbj kNXyN5leoQTGnxql+i/JoxuZUDDvVmyqcYxlKBpWbW2I34+FJEI= =QEz3 -----END PGP SIGNATURE-----