[Git][security-tracker-team/security-tracker][master] nodejs/commit

Bastien Roucariès (@rouca) rouca at debian.org
Sat Aug 15 10:22:54 BST 2026



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
edc7bf6f by Bastien Roucariès at 2026-08-15T11:21:46+02:00
nodejs/commit

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -18037,6 +18037,7 @@ CVE-2022-4994 (In the Linux kernel, the following vulnerability has been resolve
 CVE-2026-58044 (A flaw in Node.js HTTP client can cause a request desynchronization fo ...)
 	- nodejs 24.19.0+dfsg+~cs24.13.3-1
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http-parser-header-truncation-can-enable-request-smuggling-cve-2026-58044---low
+	NOTE: Fixed by: https://github.com/nodejs/node/commit/c8525ac3a6974f1db795d7fb5ac63e9f97a6fba5 (v22.23.2)
 CVE-2026-58039 (A flaw in Node.js Permission Model enforcement allows process.report w ...)
 	- nodejs 24.19.0+dfsg+~cs24.13.3-1
 	[bookworm] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
@@ -18046,6 +18047,7 @@ CVE-2026-58039 (A flaw in Node.js Permission Model enforcement allows process.re
 CVE-2026-58045 (A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigge ...)
 	- nodejs 24.19.0+dfsg+~cs24.13.3-1
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#nodezlib-sync-apis-can-crash-on-spoofed-typedarray-length-cve-2026-58045---medium
+	NOTE: Fixed by: https://github.com/nodejs/node/commit/0d072480c3dbbad6db8723e39786321646989343 (v22.23.2)
 CVE-2026-58042 (A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Proces ...)
 	- nodejs 24.19.0+dfsg+~cs24.13.3-1
 	NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#dnsresolveany-can-abort-on-dns-responses-with-many-a-records-cve-2026-58042---medium



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/edc7bf6f14b5b25945cce54697300d8f86a38e49

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/edc7bf6f14b5b25945cce54697300d8f86a38e49
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260815/8add6a41/attachment.htm>


More information about the debian-security-tracker-commits mailing list