[Git][security-tracker-team/security-tracker][master] nodejs triagging

Bastien Roucariès (@rouca) rouca at debian.org
Thu Aug 6 09:33:15 BST 2026



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2232e1d6 by Bastien Roucariès at 2026-08-06T10:25:17+02:00
nodejs triagging

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4113,6 +4113,8 @@ CVE-2026-58044 (A flaw in Node.js HTTP client can cause a request desynchronizat
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http-parser-header-truncation-can-enable-request-smuggling-cve-2026-58044---low
 CVE-2026-58039 (A flaw in Node.js Permission Model enforcement allows process.report w ...)
 	- nodejs <unfixed>
+	[bookworm] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
+	[bullseye] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#permission-model-allows-process-reports-to-write-outside-the-allowlist-cve-2026-58039---low
 CVE-2026-58045 (A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigge ...)
 	- nodejs <unfixed>
@@ -4233,6 +4235,8 @@ CVE-2026-58046 (Improper neutralization in the Plesk XML-RPC API allows a remote
 	NOT-FOR-US: Plesk
 CVE-2026-58043 (A flaw in Node.js Permission Model enforcement can over-grant filesyst ...)
 	- nodejs <unfixed>
+	[bookworm] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
+	[bullseye] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#permission-model-path-matching-can-over-grant-filesystem-access-cve-2026-58043---high
 CVE-2026-58040 (An incomplete fix has been identified in Node.js: HTTPS Agent TLS sess ...)
 	- nodejs <unfixed>
@@ -4242,6 +4246,8 @@ CVE-2026-56850 (A flaw in Node.js HTTPS Agent connection reuse can cause PFX obj
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#https-agent-can-reuse-mtls-identities-across-pfx-certificates-cve-2026-56850---medium
 CVE-2026-56847 (A flaw in Node.js Permission Model enforcement allows `trace_events.cr ...)
 	- nodejs <unfixed>
+	[bookworm] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
+	[bullseye] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#permission-model-allows-trace-events-to-write-outside-the-allowlist-cve-2026-56847---low
 CVE-2026-54249 (Pydantic AI is a Python agent framework for building Generative AI app ...)
 	NOT-FOR-US: Pydantic AI
@@ -40531,9 +40537,13 @@ CVE-2026-48931 (A flaw in Node.js HTTP Agent can cause a client to accept as val
 	NOTE: https://github.com/nodejs/node/commit/0a22d40180cb796e0d68e94c1a7a8a05a8f47c10 (v22.23.0)
 CVE-2026-48936 (A flaw in Node.js Permission API can cause a local server to be starte ...)
 	- nodejs <not-affected> (Only affects Node.js v26)
+	[bookworm] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
+	[bullseye] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
 	NOTE: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases#unix-domain-socket-server-bypasses---permission-network-restrictions-incomplete-cve-2026-21636-fix-cve-2026-48936---low
 CVE-2026-48935 (A flaw in Node.js Permission API can cause a file metadata to be modif ...)
 	- nodejs 24.17.0+dfsg+~cs24.13.2-1
+	[bookworm] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
+	[bullseye] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
 	NOTE: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases#permission-model-bypass-via-filehandleutimes-in-the-promises-api-cve-2026-48935---low
 	NOTE: https://github.com/nodejs/node/commit/28dcd388644c676b5b8149abfe18ec32cd010781 (v22.23.0)
 CVE-2026-48934 (A flaw in Node.js TLS host verification can cause an attacker to bypas ...)
@@ -40554,6 +40564,9 @@ CVE-2026-48619 (A flaw in Node.js HTTP/2 client allows a server to send an unlim
 	NOTE: https://github.com/nodejs/node/commit/c79968e108002c2394bdb9e9cefb2c8c8cc202f8 (v22.23.0)
 CVE-2026-48615 (A flaw in Node.js proxy tunnel error handling could expose proxy crede ...)
 	- nodejs 24.17.0+dfsg+~cs24.13.2-1
+	[trixie] - nodejs <not-affected> (ERR_PROXY_TUNNEL built-in proxy client is a Node 22+ feature; not present)
+	[bookworm] - nodejs <not-affected> (ERR_PROXY_TUNNEL built-in proxy client is a Node 22+ feature; not present)
+	[bullseye] - nodejs <not-affected> (ERR_PROXY_TUNNEL built-in proxy client is a Node 22+ feature; not present)
 	NOTE: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases#proxy-credentials-leaked-in-err_proxy_tunnel-error-message-cve-2026-48615---medium
 	NOTE: https://github.com/nodejs/node/commit/9b6af26132f6e87659ce360e6a59f42a03ff1701 (v22.23.0)
 CVE-2026-48618 (A flaw in Node.js TLS hostname handling can cause Node.js unicode dot  ...)
@@ -40562,6 +40575,7 @@ CVE-2026-48618 (A flaw in Node.js TLS hostname handling can cause Node.js unicod
 	NOTE: https://github.com/nodejs/node/commit/2197a47144f3356ab451c5dcd858a49eb5957a70 (v22.23.0)
 CVE-2026-48933 (A flaw in Node.js WebCrypto implementation can crash the process if th ...)
 	- nodejs 24.17.0+dfsg+~cs24.13.2-1
+	[bullseye] - nodejs <not-affected> (WebCrypto (SubtleCrypto) introduced in Node 15; not present)
 	NOTE: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases#nodejs-webcrypto-aes-integer-overflow-leads-to-remote-process-abort-dos-cve-2026-48933---high
 	NOTE: https://github.com/nodejs/node/commit/38b4c5ed51b2ec81c28fbd379fea72e22fa12a15 (v22.23.0)
 CVE-2026-9815 (The MagicForm WordPress plugin through 0.1.3 does not properly validat ...)
@@ -40670,6 +40684,8 @@ CVE-2026-48937 (A flaw in Node.js HTTP/2 server API can cause servers to keep ac
 	NOTE: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases#http2-sessions-never-clean-up-after-goaway-on-invalid-protocol-errors-cve-2026-48937---medium
 CVE-2026-48617 (A flaw in Node.js Permission Model enforcement allows Bypass via `proc ...)
 	- nodejs 24.17.0+dfsg+~cs24.13.2-1
+	[bookworm] - nodejs <not-affected> ((Permission Model is a Node 20+ feature)
+	[bullseye] - nodejs <not-affected> ((Permission Model is a Node 20+ feature)
 	NOTE: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases#permission-model-bypass-via-processreportwritereport-path-misvalidation-cve-2026-48617---low
 	NOTE: https://github.com/nodejs/node/commit/2f62693801a12bc8a485b3b7da3239ac522f607d (v22.23.0)
 CVE-2026-47833 (setupBpmLogs follows symlink for bpm.log open and chown \u2014 contain ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2232e1d64a66117f03130b7ddc5d5405bf0b89aa

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2232e1d64a66117f03130b7ddc5d5405bf0b89aa
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/4284ef0b/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list