SUSE-SU-2026:4355-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20264355-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4355-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:4355-1
Upstream
CVE (31)
Related
Published
2026-09-28T08:55:58Z
Modified
2026-09-29T09:15:08Z
Summary
Security update for nodejs16
Details

This update for nodejs16 fixes the following issues:

  • CVE-2025-23085: memory leak when remote peer abruptly closes socket without sending GOAWAY notification (bsc#1236250).
  • CVE-2025-23166: improper error handling in async cryptographic operations crashes process (bsc#1243218).
  • CVE-2025-23167: llhttp: improper HTTP header block termination in llhttp (bsc#1243220).
  • CVE-2025-55131: timeout-based race conditions allow for allocations that contain leftover data from previous operations and lead to exposure of in-process secrets (bsc#1256570).
  • CVE-2025-59465: malformed HTTP/2 HEADERS frame with invalid HPACK data can cause a crash due to an unhandled error (bsc#1256573).
  • CVE-2025-59466: uncatchable 'Maximum call stack size exceeded' error when async_hooks.createHook() is enabled can lead to crash (bsc#1256574).
  • CVE-2026-6733: undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (bsc#1268479).
  • CVE-2026-11525: undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (bsc#1268481).
  • CVE-2026-12151: undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (bsc#1268482).
  • CVE-2026-15157: No validation of the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher (bsc#1272958).
  • CVE-2026-21637: synchronous exceptions thrown during certain callbacks bypass the standard TLS error handling paths and can cause a denial of service (bsc#1256576).
  • CVE-2026-21710: uncaught TypeError exception can cause a denial of service (bsc#1260455).
  • CVE-2026-21713: timing side-channel in HMAC verification via memcmp can lead to potential MAC forgery (bsc#1260463).
  • CVE-2026-21714: WINDOW_UPDATE frames on stream 0 can lead to memory leak (bsc#1260480).
  • CVE-2026-22036: undici: unbounded decompression chain in HTTP responses via Content-Encoding may lead to resource exhaustion (bsc#1256848).
  • CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853).
  • CVE-2026-48618: Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismatch (bsc#1268593).
  • CVE-2026-48619: Unbounded memory growth in node:http2 clients via attacker-controlled ORIGIN frames (bsc#1268618).
  • CVE-2026-48928: Uppercase sni context matching can lead to mtls authorization bypass due to case-sensitive hostname matching (bsc#1268605).
  • CVE-2026-48930: Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings (bsc#1268606).
  • CVE-2026-48931: HTTP Response Queue Poisoning via TOCTOU Race Condition in http.Agent (bsc#1268611).
  • CVE-2026-48933: Node.js WebCrypto AES Integer Overflow Leads to Remote Process Abort (bsc#1268592).
  • CVE-2026-48934: TLS host identity verification bypass via session reuse with different servername leads to unauthorized connections (bsc#1268608).
  • CVE-2026-48937: servers keep accepting data even after sending a GOAWAY frame (bsc#1268555).
  • CVE-2026-56846: HTTP/2 retained headers can bypass maxSessionMemory limits (bsc#1272941).
  • CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942).
  • CVE-2026-56850: HTTPS Agent can reuse mTLS identities across PFX certificates (bsc#1272944).
  • CVE-2026-58040: HTTPS Agent session reuse can skip hostname verification (bsc#1272945).
  • CVE-2026-58042: dns.resolveAny() can abort on DNS responses with many A records (bsc#1272947).
  • CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951).
  • CVE-2026-58045: node:zlib sync APIs can crash on spoofed TypedArray length (bsc#1272948).
References

Affected packages

SUSE:Linux Enterprise High Performance Computing 15 SP4-ESPOS
nodejs16

Package

Name
nodejs16
Purl
pkg:rpm/suse/nodejs16&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
16.20.2-150400.3.42.1

Ecosystem specific

{
    "binaries": [
        {
            "nodejs16": "16.20.2-150400.3.42.1",
            "nodejs16-devel": "16.20.2-150400.3.42.1",
            "nodejs16-docs": "16.20.2-150400.3.42.1",
            "npm16": "16.20.2-150400.3.42.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4355-1.json"
SUSE:Linux Enterprise High Performance Computing 15 SP4-LTSS
nodejs16

Package

Name
nodejs16
Purl
pkg:rpm/suse/nodejs16&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
16.20.2-150400.3.42.1

Ecosystem specific

{
    "binaries": [
        {
            "nodejs16": "16.20.2-150400.3.42.1",
            "nodejs16-devel": "16.20.2-150400.3.42.1",
            "nodejs16-docs": "16.20.2-150400.3.42.1",
            "npm16": "16.20.2-150400.3.42.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4355-1.json"
SUSE:Linux Enterprise Server 15 SP4-LTSS
nodejs16

Package

Name
nodejs16
Purl
pkg:rpm/suse/nodejs16&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
16.20.2-150400.3.42.1

Ecosystem specific

{
    "binaries": [
        {
            "nodejs16": "16.20.2-150400.3.42.1",
            "nodejs16-devel": "16.20.2-150400.3.42.1",
            "nodejs16-docs": "16.20.2-150400.3.42.1",
            "npm16": "16.20.2-150400.3.42.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4355-1.json"
SUSE:Linux Enterprise Server for SAP Applications 15 SP4
nodejs16

Package

Name
nodejs16
Purl
pkg:rpm/suse/nodejs16&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
16.20.2-150400.3.42.1

Ecosystem specific

{
    "binaries": [
        {
            "nodejs16": "16.20.2-150400.3.42.1",
            "nodejs16-devel": "16.20.2-150400.3.42.1",
            "nodejs16-docs": "16.20.2-150400.3.42.1",
            "npm16": "16.20.2-150400.3.42.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:4355-1.json"