This update for nodejs24 fixes the following issues:
Update to 24.14.1
CVE-2026-21637: synchronous exceptions thrown during certain callbacks bypass the standard TLS error handling paths and can cause a denial of service (bsc#1256576).
CVE-2026-21710: uncaught TypeError exception can cause a denial of service (bsc#1260455).
CVE-2026-21712: malformed URL format can lead to a crash (bsc#1260460).
CVE-2026-21713: timing side-channel in HMAC verification via memcmp can lead to potential MAC forgery (bsc#1260463).
CVE-2026-21714: WINDOW_UPDATE frames on stream 0 can lead to memory leak (bsc#1260480).
CVE-2026-21715: permission model bypass in realpathSync.native can allow file existence disclosure (bsc#1260482).
CVE-2026-21716: promise-based FileHandle methods can be used to modify file permissions and ownership (bsc#1260462).
CVE-2026-21717: crafted request can lead to trivially predictable hash collisions (bsc#1260494).