[Git][security-tracker-team/security-tracker][master] nodejs/commit
Bastien Roucariès (@rouca)
rouca at debian.org
Sat Aug 15 10:22:54 BST 2026
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker
Commits:
edc7bf6f by Bastien Roucariès at 2026-08-15T11:21:46+02:00
nodejs/commit
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -18037,6 +18037,7 @@ CVE-2022-4994 (In the Linux kernel, the following vulnerability has been resolve
CVE-2026-58044 (A flaw in Node.js HTTP client can cause a request desynchronization fo ...)
- nodejs 24.19.0+dfsg+~cs24.13.3-1
NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http-parser-header-truncation-can-enable-request-smuggling-cve-2026-58044---low
+ NOTE: Fixed by: https://github.com/nodejs/node/commit/c8525ac3a6974f1db795d7fb5ac63e9f97a6fba5 (v22.23.2)
CVE-2026-58039 (A flaw in Node.js Permission Model enforcement allows process.report w ...)
- nodejs 24.19.0+dfsg+~cs24.13.3-1
[bookworm] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
@@ -18046,6 +18047,7 @@ CVE-2026-58039 (A flaw in Node.js Permission Model enforcement allows process.re
CVE-2026-58045 (A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigge ...)
- nodejs 24.19.0+dfsg+~cs24.13.3-1
NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#nodezlib-sync-apis-can-crash-on-spoofed-typedarray-length-cve-2026-58045---medium
+ NOTE: Fixed by: https://github.com/nodejs/node/commit/0d072480c3dbbad6db8723e39786321646989343 (v22.23.2)
CVE-2026-58042 (A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Proces ...)
- nodejs 24.19.0+dfsg+~cs24.13.3-1
NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#dnsresolveany-can-abort-on-dns-responses-with-many-a-records-cve-2026-58042---medium
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/edc7bf6f14b5b25945cce54697300d8f86a38e49
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/edc7bf6f14b5b25945cce54697300d8f86a38e49
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260815/8add6a41/attachment.htm>
More information about the debian-security-tracker-commits
mailing list