SUSE-SU-2026:0295-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20260295-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0295-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:0295-1
Upstream
  • CVE-2025-55131
Related
Published
2026-01-26T13:19:01Z
Modified
2026-03-11T07:31:32.992299Z
Summary
Security update for nodejs22
Details

This update for nodejs22 fixes the following issues:

Security fixes:

  • CVE-2026-22036: Fixed unbounded decompression chain in HTTP response leading to resource exhaustion (bsc#1256848)
  • CVE-2026-21637: Fixed synchronous exceptions thrown during callbacks that bypass TLS error handling and causing denial of service (bsc#1256576)
  • CVE-2025-55132: Fixed futimes() ability to acces file even if process has read permissions only (bsc#1256571)
  • CVE-2025-55131: Fixed race condition that allowed allocations with leftover data leading to in-process secrets exposure (bsc#1256570)
  • CVE-2025-55130: Fixed filesystem permissions bypass via crafted symlinks (bsc#1256569)
  • CVE-2025-59465: Fixed malformed HTTP/2 HEADERS frame with invalid HPACK leading to crash (bsc#1256573)
  • CVE-2025-59466: Fixed uncatchable 'Maximum call stack size exceeded' error leading to crash (bsc#1256574)

Other fixes:

  • Update to 22.22.0:

    • deps: updated undici to 6.23.0
    • deps: updated bundled c-ares to 1.34.6 (if used)
    • add TLSSocket default error handler
    • disable futimes when permission model is enabled
    • require full read and write to symlink APIs
    • rethrow stack overflow exceptions in async_hooks
    • refactor unsafe buffer creation to remove zero-fill toggle
    • route callback exceptions through error handlers
  • Update to 22.21.1:

    • src: avoid unnecessary string -> char* -> string round trips
    • src: remove unnecessary shadowed functions on Utf8Value & BufferValue
    • process: fix hrtime fast call signatures
    • http: improve writeEarlyHints by avoiding for-of loop
  • Update to 22.21.0:

    • cli: add --use-env-proxy
    • http: support http proxy for fetch under NODEUSEENV_PROXY
    • http: add shouldUpgradeCallback to let servers control HTTP upgrades
    • http,https: add built-in proxy support in http/https.request and Agent
    • src: add percentage support to --max-old-space-size
  • Update to 22.20.0

    • doc: stabilize --disable-sigusr1
    • doc: mark path.matchesGlob as stable
    • http: add Agent.agentKeepAliveTimeoutBuffer option
    • http2: add support for raw header arrays in h2Stream.respond()
    • inspector: add http2 tracking support
    • sea: implement execArgvExtension
    • sea: support execArgv in sea config
    • stream: add brotli support to CompressionStream and DecompressionStream
    • test_runner: support object property mocking
    • worker: add cpu profile APIs for worker
  • Update to 22.19.0

    • cli: add NODEUSESYSTEM_CA=1
    • cli: support ${pid} placeholder in --cpu-prof-name
    • crypto: add tls.setDefaultCACertificates()
    • dns: support max timeout
    • doc: update the instruction on how to verify releases
    • esm: unflag --experimental-wasm-modules
    • http: add server.keepAliveTimeoutBuffer option
    • lib: docs deprecate http*
    • net: update net.blocklist to allow file save and file management
    • process: add threadCpuUsage
    • zlib: add dictionary support to zstdCompress and zstdDecompress
  • Update to 22.18.0:

    • deps: update amaro to 1.1.0
    • doc: add all watch-mode related flags to node.1
    • doc: add islandryu to collaborators
    • esm: implement import.meta.main
    • fs: allow correct handling of burst in fs-events with AsyncIterator
    • permission: propagate permission model flags on spawn
    • sqlite: add support for readBigInts option in db connection level
    • src,permission: add support to permission.has(addon)
    • url: add fileURLToPathBuffer API
    • watch: add --watch-kill-signal flag
    • worker: make Worker async disposable
References

Affected packages

openSUSE:Leap 15.6
nodejs22

Package

Name
nodejs22
Purl
pkg:rpm/opensuse/nodejs22&distro=openSUSE%20Leap%2015.6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
22.22.0-150600.13.12.1

Ecosystem specific

{
    "binaries": [
        {
            "nodejs22-devel": "22.22.0-150600.13.12.1",
            "corepack22": "22.22.0-150600.13.12.1",
            "npm22": "22.22.0-150600.13.12.1",
            "nodejs22": "22.22.0-150600.13.12.1",
            "nodejs22-docs": "22.22.0-150600.13.12.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0295-1.json"
SUSE:Linux Enterprise Server 15 SP6-LTSS
nodejs22

Package

Name
nodejs22
Purl
pkg:rpm/suse/nodejs22&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
22.22.0-150600.13.12.1

Ecosystem specific

{
    "binaries": [
        {
            "nodejs22-devel": "22.22.0-150600.13.12.1",
            "npm22": "22.22.0-150600.13.12.1",
            "nodejs22": "22.22.0-150600.13.12.1",
            "nodejs22-docs": "22.22.0-150600.13.12.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0295-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP6
nodejs22

Package

Name
nodejs22
Purl
pkg:rpm/suse/nodejs22&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
22.22.0-150600.13.12.1

Ecosystem specific

{
    "binaries": [
        {
            "nodejs22-devel": "22.22.0-150600.13.12.1",
            "npm22": "22.22.0-150600.13.12.1",
            "nodejs22": "22.22.0-150600.13.12.1",
            "nodejs22-docs": "22.22.0-150600.13.12.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:0295-1.json"