-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 22 Sep 2026 19:12:18 +0200
Source: nodejs
Binary: libnode-dev libnode115 libnode115-dbgsym nodejs nodejs-dbgsym
Architecture: arm64
Version: 20.19.2+dfsg-1+deb13u3
Distribution: trixie-security
Urgency: medium
Maintainer: arm64 Build Daemon (arm-ubc-05) <buildd_arm64-arm-ubc-05@buildd.debian.org>
Changed-By: Bastien Roucariès <rouca@debian.org>
Description:
 libnode-dev - evented I/O for V8 javascript (development files)
 libnode115 - evented I/O for V8 javascript - runtime library
 nodejs     - evented I/O for V8 javascript - runtime executable
Changes:
 nodejs (20.19.2+dfsg-1+deb13u3) trixie-security; urgency=medium
 .
   * Team upload
   * Fix CVE-2026-48617:
     A flaw in Node.js Permission Model enforcement allows Bypass
     via `process.report.writeReport()` Path Misvalidation.
     This can lead to confidentiality impact or bypass of the
     intended security boundary under affected configurations.
   * Fix CVE-2026-48618:
     A flaw in Node.js TLS hostname handling can cause Node.js unicode
     dot separator handling can lead to tls wildcard-depth
     authentication bypass due to resolver and verifier hostname
     normalization mismat. This can lead to confidentiality impact
     or bypass of the intended security boundary under
     affected configurations.
   * Fix CVE-2026-48619:
     A malicious HTTP/2 server can send repeated ORIGIN frames with unique
     origins, causing unbounded growth of the client-side originSet for the
     lifetime of the session. Cap the set at 128 entries; once full, new
     origins from ORIGIN frames are silently dropped.
   * Fix CVE-2026-48928: case-sensitive SNI context matching
     The regex constructed by server.addContext() lacked the case-insensitive
     flag, causing uppercase or mixed-case SNI hostnames from ClientHello to
     miss their intended context and fall back to the default context. This
     violates RFC 6066 Section 3, which states that DNS hostnames are
     case-insensitive. In mTLS configurations with per-tenant contexts, this
     allowed bypassing client certificate authorization by simply
     uppercasing the SNI hostname.
   * Fix CVE-2026-48930:
     A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames
     can lead to silent authority rebinding due to c-string truncation
     in resolver bindings.
   * Fix CVE-2026-48931:
     HTTP Agent can cause a client to accept as valid a response
     that is send before the client has sent the request.
   * Fix CVE-2026-48933:
     A flaw in Node.js WebCrypto implementation can crash the process
     if the input of `subtle.encrypt()` is a multiple of 2GiB.
   * Fix CVE-2026-48934:
     A flaw in Node.js TLS host verification can cause an attacker
     to bypass certification validation.
   * Fix CVE-2026-48935:
     A flaw in Node.js Permission API can cause a file metadata
     to be modified even on a path that was set as read-only
     with e.g. --allow-fs-read.
   * Fix CVE-2026-48937:
     A flaw in Node.js HTTP/2 server API can cause servers
     to keep accepting data even after sending a `GOAWAY` frame.
   * Fix CVE-2026-56846
     A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained
     header blocks evade maxSessionMemory
     and enable remote memory exhaustion.
   * Fix CVE-2026-56847:
     A flaw in Node.js Permission Model enforcement allows
     trace_events.createTracing().enable() Writes Trace Logs
     Outside --allow-fs-write.
   * Fix CVE-2026-56848:
     A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()`
     to be called re-entrantly while `nghttp2_session_mem_recv()` is executing,
     resulting in a heap-use-after-free.
   * Fix CVE-2026-56850:
     A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array
     key collisions, allowing mutual TLS (mTLS) client identities to be
     reused across requests configured with different client certificates.
   * Fix CVE-2026-58039:
     A flaw in Node.js Permission Model enforcement allows process.report writes
     (and overwrites) files outside --allow-fs-write paths.
     This can lead to confidentiality impact or bypass of the intended
     security boundary under affected configurations
   * Fix CVE-2026-58043!
     A flaw in Node.js Permission Model enforcement can over-grant
     filesystem access across radix-tree prefix boundaries.
     Under `--permission`, an attacker who is granted access to one
     path can abuse boundary handling to read from or write to paths
     outside the intended filesystem allowlist.
   * Fix CVE-2026-58040:
     An incomplete fix has been identified in Node.js: HTTPS Agent
     TLS session reuse skips hostname verification across identity policies
     (incomplete fix of CVE-2026-48934).
Checksums-Sha1:
 80740dde379c5e2bd105174fa1b668db602970ae 538540 libnode-dev_20.19.2+dfsg-1+deb13u3_arm64.deb
 a1118358285efc83d48674c98330c7e2ef73bd8e 1051935384 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_arm64.deb
 0d3ada63628bdc86f3349238b3993c4f77eed400 10902960 libnode115_20.19.2+dfsg-1+deb13u3_arm64.deb
 0b68d76bd661a98c76fa23b7b03f258218629c94 82692 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_arm64.deb
 5db99ba057a31d0fcff70c76100c5cbd3e437800 11209 nodejs_20.19.2+dfsg-1+deb13u3_arm64-buildd.buildinfo
 956653f3f4f8c2d9b9456c179091ca6ab1ac8907 354892 nodejs_20.19.2+dfsg-1+deb13u3_arm64.deb
Checksums-Sha256:
 cbcf4c7729b7044bfd2e62e952ade5dd043e9c26dfddcad6e3c36dc70fee79db 538540 libnode-dev_20.19.2+dfsg-1+deb13u3_arm64.deb
 3d211d2b1c138e3ae534f7a8fc159f3f1b2ed1755e43683971113c05eb46b32c 1051935384 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_arm64.deb
 5ac5229d5cb4c2b5fd4416878bea5833e5ad6ef6b01eb228d25ae1f8ca6a15ba 10902960 libnode115_20.19.2+dfsg-1+deb13u3_arm64.deb
 02177d9eb84cb2fec9931bce275634de87ede558c0fbe3196754d3cce8348446 82692 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_arm64.deb
 bccfdd34aa003717327e4313f71cdb7e4bd91c2279496c80fea05507bbd02aad 11209 nodejs_20.19.2+dfsg-1+deb13u3_arm64-buildd.buildinfo
 a92077b99707d2199342a197a58f4a8aa78b213ff7e0906653c958f42da163e2 354892 nodejs_20.19.2+dfsg-1+deb13u3_arm64.deb
Files:
 d40f1a7c3fcbd7d6cf990ef10412f7de 538540 libdevel optional libnode-dev_20.19.2+dfsg-1+deb13u3_arm64.deb
 ce5c0a92773084ca1dcbb04793812709 1051935384 debug optional libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_arm64.deb
 ecadb528913e4d84973ea7125cc70e15 10902960 libs optional libnode115_20.19.2+dfsg-1+deb13u3_arm64.deb
 c392fe945876f36cd2d4d968f9c0a1fd 82692 debug optional nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_arm64.deb
 0770b4156ab4f15625e0125403eb82de 11209 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_arm64-buildd.buildinfo
 6b4bf813b84f0a31885c7094132134d0 354892 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_arm64.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7rv+l3KtZdQea77lnwznazfjXToFAmq8MQwACgkQnwznazfj
XTqTiRAA5Ch8jaFuw75gbGl4PlGBWLfARZuf5eLyPp0qVvLtZeIz28VB6K1jB6EL
zXOtx5KDm/T904ZDkDLwsMMNexXIGLVCG7xwWhBw3RM6ik1ADygEwlWWcKhwXYb0
84HKngIGT7s5P2ovNansQvSGtX/zFz1DbRAGI07vsJanEnLoy1SnEUJikUDmRNCZ
Gf0MYfrX/ZM67AGZVcUdfs5HYKYLYdZZD8+OqgtU1yA4iXLGUqQQT0kRj2cxerw3
dZi0jov8RzXK/qGd5Q5Rw0G/2PtZNcfqRnJFxFGyg7YHiaxyKjgi8AbO2pvXYt7K
s6/PAtt27yA080xZXKgyQi47+zIz+TYZaH5kK7CutAMnb2t2r1vL/67IkD0rl0Vl
7RM7HgH02HpCyLBwzN6GRmcNUz5QvCJR0livqixjiJHrlKNqZzv8Wv87dRd2JeAH
HLZ2o32hpzBaJIa1DSIS5r1ik2p/HUbNokyzHM4fNUw+UPjlXUxxhGGGBwb10IGn
UeLixcX22KVSgUFnwOAfvkSPxvgs8cHzkp36x28dmzM6GEorjq4mNUxLB4S/fisb
yoN1EvPaLBDYamG1n/uzzqWsIZFe49vbaX+QSL3Wy4Jw0dP09yW/dN6hmTH7sQYL
S92tgJs8cK8jb/UXhwEQ1FTJWPxYzeuqz2fdbO0+OoIqHGtDG9c=
=IRUZ
-----END PGP SIGNATURE-----
