-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 22 Sep 2026 19:12:18 +0200
Source: nodejs
Binary: libnode-dev libnode115 libnode115-dbgsym nodejs nodejs-dbgsym
Architecture: s390x
Version: 20.19.2+dfsg-1+deb13u3
Distribution: trixie-security
Urgency: medium
Maintainer: s390x Build Daemon (ziehrer) <buildd_s390x-ziehrer@buildd.debian.org>
Changed-By: Bastien Roucariès <rouca@debian.org>
Description:
 libnode-dev - evented I/O for V8 javascript (development files)
 libnode115 - evented I/O for V8 javascript - runtime library
 nodejs     - evented I/O for V8 javascript - runtime executable
Changes:
 nodejs (20.19.2+dfsg-1+deb13u3) trixie-security; urgency=medium
 .
   * Team upload
   * Fix CVE-2026-48617:
     A flaw in Node.js Permission Model enforcement allows Bypass
     via `process.report.writeReport()` Path Misvalidation.
     This can lead to confidentiality impact or bypass of the
     intended security boundary under affected configurations.
   * Fix CVE-2026-48618:
     A flaw in Node.js TLS hostname handling can cause Node.js unicode
     dot separator handling can lead to tls wildcard-depth
     authentication bypass due to resolver and verifier hostname
     normalization mismat. This can lead to confidentiality impact
     or bypass of the intended security boundary under
     affected configurations.
   * Fix CVE-2026-48619:
     A malicious HTTP/2 server can send repeated ORIGIN frames with unique
     origins, causing unbounded growth of the client-side originSet for the
     lifetime of the session. Cap the set at 128 entries; once full, new
     origins from ORIGIN frames are silently dropped.
   * Fix CVE-2026-48928: case-sensitive SNI context matching
     The regex constructed by server.addContext() lacked the case-insensitive
     flag, causing uppercase or mixed-case SNI hostnames from ClientHello to
     miss their intended context and fall back to the default context. This
     violates RFC 6066 Section 3, which states that DNS hostnames are
     case-insensitive. In mTLS configurations with per-tenant contexts, this
     allowed bypassing client certificate authorization by simply
     uppercasing the SNI hostname.
   * Fix CVE-2026-48930:
     A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames
     can lead to silent authority rebinding due to c-string truncation
     in resolver bindings.
   * Fix CVE-2026-48931:
     HTTP Agent can cause a client to accept as valid a response
     that is send before the client has sent the request.
   * Fix CVE-2026-48933:
     A flaw in Node.js WebCrypto implementation can crash the process
     if the input of `subtle.encrypt()` is a multiple of 2GiB.
   * Fix CVE-2026-48934:
     A flaw in Node.js TLS host verification can cause an attacker
     to bypass certification validation.
   * Fix CVE-2026-48935:
     A flaw in Node.js Permission API can cause a file metadata
     to be modified even on a path that was set as read-only
     with e.g. --allow-fs-read.
   * Fix CVE-2026-48937:
     A flaw in Node.js HTTP/2 server API can cause servers
     to keep accepting data even after sending a `GOAWAY` frame.
   * Fix CVE-2026-56846
     A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained
     header blocks evade maxSessionMemory
     and enable remote memory exhaustion.
   * Fix CVE-2026-56847:
     A flaw in Node.js Permission Model enforcement allows
     trace_events.createTracing().enable() Writes Trace Logs
     Outside --allow-fs-write.
   * Fix CVE-2026-56848:
     A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()`
     to be called re-entrantly while `nghttp2_session_mem_recv()` is executing,
     resulting in a heap-use-after-free.
   * Fix CVE-2026-56850:
     A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array
     key collisions, allowing mutual TLS (mTLS) client identities to be
     reused across requests configured with different client certificates.
   * Fix CVE-2026-58039:
     A flaw in Node.js Permission Model enforcement allows process.report writes
     (and overwrites) files outside --allow-fs-write paths.
     This can lead to confidentiality impact or bypass of the intended
     security boundary under affected configurations
   * Fix CVE-2026-58043!
     A flaw in Node.js Permission Model enforcement can over-grant
     filesystem access across radix-tree prefix boundaries.
     Under `--permission`, an attacker who is granted access to one
     path can abuse boundary handling to read from or write to paths
     outside the intended filesystem allowlist.
   * Fix CVE-2026-58040:
     An incomplete fix has been identified in Node.js: HTTPS Agent
     TLS session reuse skips hostname verification across identity policies
     (incomplete fix of CVE-2026-48934).
Checksums-Sha1:
 1da9d760735bcffc80c70afb7f8f6216c468c0d9 538536 libnode-dev_20.19.2+dfsg-1+deb13u3_s390x.deb
 6d98484df1e6aed3f5d7386a7df1f888aef8aaa1 1078168848 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_s390x.deb
 25611bb02b459a3d0f69ceb81fc1148f93aaf13e 12211888 libnode115_20.19.2+dfsg-1+deb13u3_s390x.deb
 2b31a088547e5effbddfc3446b3e20acd17eb8a4 82552 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_s390x.deb
 916ff2d557b3088f3d943192211579e9f5a9ef29 11087 nodejs_20.19.2+dfsg-1+deb13u3_s390x-buildd.buildinfo
 217405e96bf5f7b08bbbaf27633b6b9d31f06e82 354668 nodejs_20.19.2+dfsg-1+deb13u3_s390x.deb
Checksums-Sha256:
 0fdc4434cda455163a37ff50005e5f9dfd238d2a02a9d493cfb0a954b2e80b03 538536 libnode-dev_20.19.2+dfsg-1+deb13u3_s390x.deb
 26ebb68f3f910f308e1264364a8c626a3c03a7602881a1d4ca15d9f9a9961830 1078168848 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_s390x.deb
 baa14c637fb38f5b0106383e9ece43b99425d756e55ff7dc9fddcc0be47ab319 12211888 libnode115_20.19.2+dfsg-1+deb13u3_s390x.deb
 d0645c5a8bbaff881288005c0a3b8ecfc5f9655297fb0597b8c9d7588b8dffed 82552 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_s390x.deb
 e79441e38a54ff928c98a4241ce2c1d4b34e21e7ac20ea26ef19707dd4bbd79f 11087 nodejs_20.19.2+dfsg-1+deb13u3_s390x-buildd.buildinfo
 9f1a60e07de2b52c1cbe870e03c9ac5ea4b4892f2a91b31398e57f79b7598371 354668 nodejs_20.19.2+dfsg-1+deb13u3_s390x.deb
Files:
 1687e274ba4bd39de1fcf099df7ffb9b 538536 libdevel optional libnode-dev_20.19.2+dfsg-1+deb13u3_s390x.deb
 a6e8f831ff9e53f415cd3e1de1eb0b6d 1078168848 debug optional libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_s390x.deb
 377421a7d6cfe2ae0f5735f97724c010 12211888 libs optional libnode115_20.19.2+dfsg-1+deb13u3_s390x.deb
 0a1840400b3485dbbe6e3eb9b828c589 82552 debug optional nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_s390x.deb
 ec0fa8ef7de0b68cf587af6556804cd6 11087 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_s390x-buildd.buildinfo
 c3d37f3928289b280aa31d020c90e3a0 354668 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_s390x.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEl0BM/nR+Oj597wRWMWUFebkHnoQFAmqzCaUACgkQMWUFebkH
noR7vA//UZDfMrNM/Ai7d17oTmDF/CSFc3Uwz6hfltDXq85/X1IsslhAgFjQIapf
aEYDvQOEb4wnWhHS/bB74Hr/IX2ZPLufuDKnodh+JeyYEn58E+DDFW1b99PKPGMt
AYcds5+AtdUImUHvVy4owtW7rU28Ww2mOzqCTXfT87PCGz67BXxinUWOY2XacxIi
o5oNBcbNqrOvN8AuwRDE/McdbYmjCNgqAjWsRxzyOUhcKpr1VLJ4BEBXqKOGW3z+
q/nNlIR8fOHDyBaq9Xg+IsIolCnRyzOtD96kAhbMEwhTlTLyrZdoc571cQnsYPl4
tbUIzP06PVl+l8KDYx0u4Lahv0+Kr5pG+atYxrDV+1sH/vOP49/bBVAEJeHfTymG
daL29dBgQpALPFr5V14glKx9JmS5nniVwWOjUl8AJOmS86UrKm05tEHjRuWRUfA+
1i5YuqGfd7zs7tpSlKEf0fdPpxoGs4zWYfgwCMMsecPfWf9HIChRaoaDBImLxjbm
XDXL/mgBJ4ZJtQLLgqmsG+Lwg3WLC3W4Bbi3pnC7kKEqJtpjSGNo1fBi2mYrs4kE
S14jFc6UbQWOVrHcdVdOTWMazMAqdnxtrtW/5zGnxv+xCl7hM25H4jQR1DOChMUs
DO+OrDnd4wgpkP6osCPe4jPK3eLsEWvcE9rqRD3x5KcZXEHa7Ow=
=p7Sj
-----END PGP SIGNATURE-----
