SUSE-SU-2026:1363-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20261363-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1363-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:1363-1
Upstream
CVE (7)
Related
Published
2026-04-15T14:16:20Z
Modified
2026-04-16T08:31:00Z
Summary
Security update for nodejs20
Details

This update for nodejs20 fixes the following issues:

Update to version 20.20.2.

  • CVE-2026-21717: trivially predictable hash collisions due to flaw in V8's string hashing mechanism allows for performance degradation via a crafted request (bsc#1260494).
  • CVE-2026-21716: incomplete fix for CVE-2024-36137 allows promise-based FileHandle methods to be used to modify file permissions and ownership on already-open file descriptors (bsc#1260462).
  • CVE-2026-21715: flaw in the Permission Model filesystem enforcement allows for file existence disclosure and filesystem path enumeration via fs.realpathSync.native() (bsc#1260482).
  • CVE-2026-21714: memory leak in Node.js HTTP/2 server allows for resource exhaustion via WINDOW_UPDATE frames sent on stream 0 (bsc#1260480).
  • CVE-2026-21713: timing side-channel due to flaw in Node.js HMAC verification allows for discovery of HMAC values and potential MAC forgery (bsc#1260463).
  • CVE-2026-21710: uncaught TypeError when handling HTTP requests allows for a process crash via requests with a header named __proto__ when the application accesses req.headersDistinct (bsc#1260455).
  • CVE-2026-21637: flaw in TLS error handling allows for resource exhaustion and crash when pskCallback or ALPNCallback are in use (bsc#1256576).
References

Affected packages

SUSE:Linux Enterprise Server 15 SP6-LTSS / nodejs20

Package

Name
nodejs20
Purl
pkg:rpm/suse/nodejs20&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20.20.2-150600.3.18.1

Ecosystem specific

{
    "binaries": [
        {
            "nodejs20": "20.20.2-150600.3.18.1",
            "nodejs20-devel": "20.20.2-150600.3.18.1",
            "nodejs20-docs": "20.20.2-150600.3.18.1",
            "npm20": "20.20.2-150600.3.18.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1363-1.json"

SUSE:Linux Enterprise Server for SAP Applications 15 SP6 / nodejs20

Package

Name
nodejs20
Purl
pkg:rpm/suse/nodejs20&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20.20.2-150600.3.18.1

Ecosystem specific

{
    "binaries": [
        {
            "nodejs20": "20.20.2-150600.3.18.1",
            "nodejs20-devel": "20.20.2-150600.3.18.1",
            "nodejs20-docs": "20.20.2-150600.3.18.1",
            "npm20": "20.20.2-150600.3.18.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1363-1.json"