SUSE-SU-2026:3930-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20263930-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3930-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:3930-1
Upstream
CVE (35)
Related
Published
2026-09-03T07:19:02Z
Modified
2026-09-10T18:23:44Z
Summary
Security update for nodejs20
Details

This update for nodejs20 fixes the following issues:

  • CVE-2025-22150: undici: predictable random values used when defining the boundary for a multipart/form-data request (bsc#1236258).
  • CVE-2026-6733: undici: response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (bsc#1268479).
  • CVE-2026-9496: pacote: excessive CPU consumption in addGitSha when processing a specially crafted spec.rawSpec value can lead to DoS (bsc#1266318).
  • CVE-2026-9679: undici: HTTP header injection via Set-Cookie percent-decoding (bsc#1268477).
  • CVE-2026-11525: undici: weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (bsc#1268481).
  • CVE-2026-12151: undici: denial of service due to unbounded memory growth via WebSocket frames (bsc#1268482).
  • CVE-2026-16728: undici: downstream response desynchronization via retry interceptor (bsc#1273593).
  • CVE-2026-16729: undici: setCookie function does not fully sanitize cookie attributes (bsc#1273591).
  • CVE-2026-22036: undici: unbounded decompression chain in HTTP responses via Content-Encoding may lead to resource exhaustion (bsc#1256848).
  • CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853).
  • CVE-2026-40170: ngtcp2: qlog parameters_set stack buffer overflow (bsc#1262274).
  • CVE-2026-42338: ip-address: cross-site scripting via improper HTML escaping of untrusted input (bsc#1268097).
  • CVE-2026-48615: proxy credentials leaked in ERR_PROXY_TUNNEL error message (bsc#1268598).
  • CVE-2026-48617: permission model enforcement bypass via process.report.writeReport() path misvalidation (bsc#1268554).
  • CVE-2026-48618: unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismatch (bsc#1268593).
  • CVE-2026-48619: unbounded memory growth in node:http2 clients via attacker-controlled ORIGIN frames (bsc#1268618).
  • CVE-2026-48928: uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname matching (bsc#1268605).
  • CVE-2026-48930: embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings (bsc#1268606).
  • CVE-2026-48931: HTTP response queue poisoning via TOCTOU race condition in http.Agent (bsc#1268611).
  • CVE-2026-48933: WebCrypto AES integer overflow leads to remote process abort (bsc#1268592).
  • CVE-2026-48934: TLS host identity verification bypass via session reuse with different servername leads to unauthorized connections (bsc#1268608).
  • CVE-2026-48935: permission model bypass via FileHandle.utimes() in the promises API (bsc#1268609).
  • CVE-2026-48937: servers keep accepting data even after sending a GOAWAY frame (bsc#1268555).
  • CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust- boundary checks (bsc#1272882).
  • CVE-2026-56846: HTTP/2 retained headers can bypass maxSessionMemory limits (bsc#1272941).
  • CVE-2026-56847: permission model allows trace events to write outside the allowlist (bsc#1272949).
  • CVE-2026-56848: HTTP/2 re-entrant send can cause heap use-after-free (bsc#1272942).
  • CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944).
  • CVE-2026-58039: permission model allows process reports to write outside the allowlist (bsc#1272950).
  • CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945).
  • CVE-2026-58042: dns.resolveAny() can abort on DNS responses with many A records (bsc#1272947).
  • CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943).
  • CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951).
  • CVE-2026-58045: node:zlib sync APIs can crash on spoofed TypedArray length (bsc#1272948).
  • CVE-2026-69192: ip-address: Address4 decodes leading-zero octets as decimal while resolvers decode them as octal, which allows for SSRF and trust-boundary bypass (bsc#1277587).
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP5-ESPOS
nodejs20

Package

Name
nodejs20
Purl
pkg:rpm/suse/nodejs20&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20.20.2-150500.11.30.1

Ecosystem specific

{
    "binaries":  [
        {
            "nodejs20":  "20.20.2-150500.11.30.1",
            "nodejs20-devel":  "20.20.2-150500.11.30.1",
            "nodejs20-docs":  "20.20.2-150500.11.30.1",
            "npm20":  "20.20.2-150500.11.30.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3930-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP5-LTSS
nodejs20

Package

Name
nodejs20
Purl
pkg:rpm/suse/nodejs20&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20.20.2-150500.11.30.1

Ecosystem specific

{
    "binaries":  [
        {
            "nodejs20":  "20.20.2-150500.11.30.1",
            "nodejs20-devel":  "20.20.2-150500.11.30.1",
            "nodejs20-docs":  "20.20.2-150500.11.30.1",
            "npm20":  "20.20.2-150500.11.30.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3930-1.json"
SUSE:Linux Enterprise Server 15 SP5-LTSS
nodejs20

Package

Name
nodejs20
Purl
pkg:rpm/suse/nodejs20&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20.20.2-150500.11.30.1

Ecosystem specific

{
    "binaries":  [
        {
            "nodejs20":  "20.20.2-150500.11.30.1",
            "nodejs20-devel":  "20.20.2-150500.11.30.1",
            "nodejs20-docs":  "20.20.2-150500.11.30.1",
            "npm20":  "20.20.2-150500.11.30.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3930-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP5
nodejs20

Package

Name
nodejs20
Purl
pkg:rpm/suse/nodejs20&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
20.20.2-150500.11.30.1

Ecosystem specific

{
    "binaries":  [
        {
            "nodejs20":  "20.20.2-150500.11.30.1",
            "nodejs20-devel":  "20.20.2-150500.11.30.1",
            "nodejs20-docs":  "20.20.2-150500.11.30.1",
            "npm20":  "20.20.2-150500.11.30.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:3930-1.json"