RHSA-2026:74085

Vulnerability from csaf_opensuse - Published: 2026-09-30 00:00 - Updated: 2026-10-02 10:42
Summary
security update for nodejs
Severity
Important
Notes
Title of the patch: security update for nodejs
Description of the patch: This security update provides a functional equivalent of RHSA-2026:74085. The original Red Hat(R) advisory is available from the Red Hat web site at https://access.redhat.com/errata/RHSA-2026:74085.
Patchnames: RHSA-2026:74085
Terms of use: CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
Affected products
Product Identifier Version Remediation
Unresolved product id: SUSE Liberty Linux 8:nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24 —
Vendor Fix
Unresolved product id: SUSE Liberty Linux 8:nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24 —
Vendor Fix
Unresolved product id: SUSE Liberty Linux 8:nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24 —
Vendor Fix
Unresolved product id: SUSE Liberty Linux 8:nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24 —
Vendor Fix
Unresolved product id: SUSE Liberty Linux 8:nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24 —
Vendor Fix
Unresolved product id: SUSE Liberty Linux 8:nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24 —
Vendor Fix
Unresolved product id: SUSE Liberty Linux 8:nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24 —
Vendor Fix
Unresolved product id: SUSE Liberty Linux 8:nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24 —
Vendor Fix
Unresolved product id: SUSE Liberty Linux 8:npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24 —
Vendor Fix
Unresolved product id: SUSE Liberty Linux 8:v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24 —
Vendor Fix
Threats
Impact important
Affected products
Recommended 10 products, the same list as for CVE-2026-19534
Threats
Impact important
Affected products
Recommended 10 products, the same list as for CVE-2026-19534
Threats
Impact important

{
  "document": {
    "aggregate_severity": {
      "namespace": "https://www.suse.com/support/security/rating/",
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "Copyright 2024 SUSE LLC. All rights reserved.",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "summary",
        "text": "security update for nodejs",
        "title": "Title of the patch"
      },
      {
        "category": "description",
        "text": "This security update provides a functional equivalent of RHSA-2026:74085.\nThe original Red Hat(R) advisory is available from the Red Hat web site at\nhttps://access.redhat.com/errata/RHSA-2026:74085.\n",
        "title": "Description of the patch"
      },
      {
        "category": "details",
        "text": "RHSA-2026:74085",
        "title": "Patchnames"
      },
      {
        "category": "legal_disclaimer",
        "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).",
        "title": "Terms of use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://www.suse.com/support/security/contact/",
      "name": "SUSE Product Security Team",
      "namespace": "https://www.suse.com/"
    },
    "references": [
      {
        "category": "external",
        "summary": "SUSE ratings",
        "url": "https://www.suse.com/support/security/rating/"
      },
      {
        "category": "self",
        "summary": "URL of this CSAF notice",
        "url": "https://ftp.suse.com/pub/projects/security/csaf/rhsa-2026_74085.json"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-19534 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-19534/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-84961 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-84961/"
      },
      {
        "category": "self",
        "summary": "SUSE CVE CVE-2026-85152 page",
        "url": "https://www.suse.com/security/cve/CVE-2026-85152/"
      }
    ],
    "title": "security update for nodejs",
    "tracking": {
      "current_release_date": "2026-10-02T10:42:18Z",
      "generator": {
        "date": "2026-09-30T00:00:00Z",
        "engine": {
          "name": "cve-database.git:bin/generate-csaf.pl",
          "version": "1"
        }
      },
      "id": "RHSA-2026:74085",
      "initial_release_date": "2026-09-30T00:00:00Z",
      "revision_history": [
        {
          "date": "2026-09-30T00:00:00Z",
          "number": "1",
          "summary": "Current version"
        },
        {
          "date": "2026-10-02T10:42:18Z",
          "number": "2",
          "summary": "unknown changes"
        }
      ],
      "status": "final",
      "version": "2"
    }
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
                "product": {
                  "name": "nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch (nodejs:24)",
                  "product_id": "nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/nodejs-docs@24.21.0-1.module+el8.10.0+24927+ed3d907a?arch=noarch\u0026rpmmod=nodejs:24:8000020261001012039:rhel8\u0026epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
                "product": {
                  "name": "nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch (nodejs:24)",
                  "product_id": "nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/nodejs-nodemon@3.1.14-2.module+el8.10.0+24711+b610b202?arch=noarch\u0026rpmmod=nodejs:24:8000020261001012039:rhel8"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
                "product": {
                  "name": "nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch (nodejs:24)",
                  "product_id": "nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/nodejs-packaging@2021.06-6.module+el8.10.0+24711+b610b202?arch=noarch\u0026rpmmod=nodejs:24:8000020261001012039:rhel8"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
                "product": {
                  "name": "nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch (nodejs:24)",
                  "product_id": "nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/nodejs-packaging-bundler@2021.06-6.module+el8.10.0+24711+b610b202?arch=noarch\u0026rpmmod=nodejs:24:8000020261001012039:rhel8"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
                "product": {
                  "name": "npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch (nodejs:24)",
                  "product_id": "npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/npm@11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a?arch=noarch\u0026rpmmod=nodejs:24:8000020261001012039:rhel8\u0026epoch=1"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
                "product": {
                  "name": "nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64 (nodejs:24)",
                  "product_id": "nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:a:nodejs:node.js:24.21.0:*:*:*:-:*:*:*",
                    "purl": "pkg:rpm/suse/nodejs@24.21.0-1.module+el8.10.0+24927+ed3d907a?arch=x86_64\u0026rpmmod=nodejs:24:8000020261001012039:rhel8\u0026epoch=1\u0026upstream=nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.src.rpm"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
                "product": {
                  "name": "nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64 (nodejs:24)",
                  "product_id": "nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/nodejs-devel@24.21.0-1.module+el8.10.0+24927+ed3d907a?arch=x86_64\u0026rpmmod=nodejs:24:8000020261001012039:rhel8\u0026epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
                "product": {
                  "name": "nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64 (nodejs:24)",
                  "product_id": "nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/nodejs-full-i18n@24.21.0-1.module+el8.10.0+24927+ed3d907a?arch=x86_64\u0026rpmmod=nodejs:24:8000020261001012039:rhel8\u0026epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
                "product": {
                  "name": "nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64 (nodejs:24)",
                  "product_id": "nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/nodejs-libs@24.21.0-1.module+el8.10.0+24927+ed3d907a?arch=x86_64\u0026rpmmod=nodejs:24:8000020261001012039:rhel8\u0026epoch=1"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
                "product": {
                  "name": "v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64 (nodejs:24)",
                  "product_id": "v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/suse/v8-13.6-devel@13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a?arch=x86_64\u0026rpmmod=nodejs:24:8000020261001012039:rhel8\u0026epoch=3"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_name",
                "name": "SUSE Liberty Linux 8",
                "product": {
                  "name": "SUSE Liberty Linux 8",
                  "product_id": "SUSE Liberty Linux 8",
                  "product_identification_helper": {
                    "cpe": "cpe:/o:suse:sll:8"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "SUSE Linux Enterprise"
          }
        ],
        "category": "vendor",
        "name": "SUSE"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24 as component of SUSE Liberty Linux 8",
          "product_id": "SUSE Liberty Linux 8:nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24"
        },
        "product_reference": "nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
        "relates_to_product_reference": "SUSE Liberty Linux 8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24 as component of SUSE Liberty Linux 8",
          "product_id": "SUSE Liberty Linux 8:nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24"
        },
        "product_reference": "nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
        "relates_to_product_reference": "SUSE Liberty Linux 8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24 as component of SUSE Liberty Linux 8",
          "product_id": "SUSE Liberty Linux 8:nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24"
        },
        "product_reference": "nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
        "relates_to_product_reference": "SUSE Liberty Linux 8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24 as component of SUSE Liberty Linux 8",
          "product_id": "SUSE Liberty Linux 8:nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24"
        },
        "product_reference": "nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
        "relates_to_product_reference": "SUSE Liberty Linux 8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24 as component of SUSE Liberty Linux 8",
          "product_id": "SUSE Liberty Linux 8:nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24"
        },
        "product_reference": "nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
        "relates_to_product_reference": "SUSE Liberty Linux 8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24 as component of SUSE Liberty Linux 8",
          "product_id": "SUSE Liberty Linux 8:nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24"
        },
        "product_reference": "nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
        "relates_to_product_reference": "SUSE Liberty Linux 8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24 as component of SUSE Liberty Linux 8",
          "product_id": "SUSE Liberty Linux 8:nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24"
        },
        "product_reference": "nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
        "relates_to_product_reference": "SUSE Liberty Linux 8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24 as component of SUSE Liberty Linux 8",
          "product_id": "SUSE Liberty Linux 8:nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24"
        },
        "product_reference": "nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
        "relates_to_product_reference": "SUSE Liberty Linux 8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24 as component of SUSE Liberty Linux 8",
          "product_id": "SUSE Liberty Linux 8:npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24"
        },
        "product_reference": "npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
        "relates_to_product_reference": "SUSE Liberty Linux 8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24 as component of SUSE Liberty Linux 8",
          "product_id": "SUSE Liberty Linux 8:v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24"
        },
        "product_reference": "v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
        "relates_to_product_reference": "SUSE Liberty Linux 8"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-19534",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-19534"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "undici\u0027s WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server\u0027s 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node\u0027s default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Liberty Linux 8:nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
          "SUSE Liberty Linux 8:npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
          "SUSE Liberty Linux 8:v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-19534",
          "url": "https://www.suse.com/security/cve/CVE-2026-19534"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1279513 for CVE-2026-19534",
          "url": "https://bugzilla.suse.com/1279513"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Liberty Linux 8:nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
            "SUSE Liberty Linux 8:v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "SUSE Liberty Linux 8:nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
            "SUSE Liberty Linux 8:v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T00:00:00Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-19534"
    },
    {
      "cve": "CVE-2026-84961",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-84961"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "undici\u0027s BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application\u0027s custom checkServerIdentity was written to reject, but which still passes Node\u0027s default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Liberty Linux 8:nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
          "SUSE Liberty Linux 8:npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
          "SUSE Liberty Linux 8:v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-84961",
          "url": "https://www.suse.com/security/cve/CVE-2026-84961"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1279831 for CVE-2026-84961",
          "url": "https://bugzilla.suse.com/1279831"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Liberty Linux 8:nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
            "SUSE Liberty Linux 8:v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "SUSE Liberty Linux 8:nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
            "SUSE Liberty Linux 8:v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T00:00:00Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-84961"
    },
    {
      "cve": "CVE-2026-85152",
      "ids": [
        {
          "system_name": "SUSE CVE Page",
          "text": "https://www.suse.com/security/cve/CVE-2026-85152"
        }
      ],
      "notes": [
        {
          "category": "general",
          "text": "undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2.",
          "title": "CVE description"
        }
      ],
      "product_status": {
        "recommended": [
          "SUSE Liberty Linux 8:nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
          "SUSE Liberty Linux 8:nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
          "SUSE Liberty Linux 8:npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
          "SUSE Liberty Linux 8:v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24"
        ]
      },
      "references": [
        {
          "category": "external",
          "summary": "CVE-2026-85152",
          "url": "https://www.suse.com/security/cve/CVE-2026-85152"
        },
        {
          "category": "external",
          "summary": "SUSE Bug 1279831 for CVE-2026-85152",
          "url": "https://bugzilla.suse.com/1279831"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n",
          "product_ids": [
            "SUSE Liberty Linux 8:nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
            "SUSE Liberty Linux 8:v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "baseScore": 7.4,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "products": [
            "SUSE Liberty Linux 8:nodejs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-devel-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-docs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-full-i18n-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-libs-1:24.21.0-1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-nodemon-0:3.1.14-2.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-packaging-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:nodejs-packaging-bundler-0:2021.06-6.module+el8.10.0+24711+b610b202.noarch::nodejs:24",
            "SUSE Liberty Linux 8:npm-1:11.19.0-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.noarch::nodejs:24",
            "SUSE Liberty Linux 8:v8-13.6-devel-3:13.6.233.17-1.24.21.0.1.module+el8.10.0+24927+ed3d907a.x86_64::nodejs:24"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "date": "2026-09-30T00:00:00Z",
          "details": "important"
        }
      ],
      "title": "CVE-2026-85152"
    }
  ]
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…