-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 22 Sep 2026 19:12:18 +0200
Source: nodejs
Binary: libnode-dev libnode115 libnode115-dbgsym nodejs nodejs-dbgsym
Architecture: i386
Version: 20.19.2+dfsg-1+deb13u3
Distribution: trixie-security
Urgency: medium
Maintainer: all / amd64 / i386 Build Daemon (x86-conova-02) <buildd_amd64-x86-conova-02@buildd.debian.org>
Changed-By: Bastien Roucariès <rouca@debian.org>
Description:
 libnode-dev - evented I/O for V8 javascript (development files)
 libnode115 - evented I/O for V8 javascript - runtime library
 nodejs     - evented I/O for V8 javascript - runtime executable
Changes:
 nodejs (20.19.2+dfsg-1+deb13u3) trixie-security; urgency=medium
 .
   * Team upload
   * Fix CVE-2026-48617:
     A flaw in Node.js Permission Model enforcement allows Bypass
     via `process.report.writeReport()` Path Misvalidation.
     This can lead to confidentiality impact or bypass of the
     intended security boundary under affected configurations.
   * Fix CVE-2026-48618:
     A flaw in Node.js TLS hostname handling can cause Node.js unicode
     dot separator handling can lead to tls wildcard-depth
     authentication bypass due to resolver and verifier hostname
     normalization mismat. This can lead to confidentiality impact
     or bypass of the intended security boundary under
     affected configurations.
   * Fix CVE-2026-48619:
     A malicious HTTP/2 server can send repeated ORIGIN frames with unique
     origins, causing unbounded growth of the client-side originSet for the
     lifetime of the session. Cap the set at 128 entries; once full, new
     origins from ORIGIN frames are silently dropped.
   * Fix CVE-2026-48928: case-sensitive SNI context matching
     The regex constructed by server.addContext() lacked the case-insensitive
     flag, causing uppercase or mixed-case SNI hostnames from ClientHello to
     miss their intended context and fall back to the default context. This
     violates RFC 6066 Section 3, which states that DNS hostnames are
     case-insensitive. In mTLS configurations with per-tenant contexts, this
     allowed bypassing client certificate authorization by simply
     uppercasing the SNI hostname.
   * Fix CVE-2026-48930:
     A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames
     can lead to silent authority rebinding due to c-string truncation
     in resolver bindings.
   * Fix CVE-2026-48931:
     HTTP Agent can cause a client to accept as valid a response
     that is send before the client has sent the request.
   * Fix CVE-2026-48933:
     A flaw in Node.js WebCrypto implementation can crash the process
     if the input of `subtle.encrypt()` is a multiple of 2GiB.
   * Fix CVE-2026-48934:
     A flaw in Node.js TLS host verification can cause an attacker
     to bypass certification validation.
   * Fix CVE-2026-48935:
     A flaw in Node.js Permission API can cause a file metadata
     to be modified even on a path that was set as read-only
     with e.g. --allow-fs-read.
   * Fix CVE-2026-48937:
     A flaw in Node.js HTTP/2 server API can cause servers
     to keep accepting data even after sending a `GOAWAY` frame.
   * Fix CVE-2026-56846
     A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained
     header blocks evade maxSessionMemory
     and enable remote memory exhaustion.
   * Fix CVE-2026-56847:
     A flaw in Node.js Permission Model enforcement allows
     trace_events.createTracing().enable() Writes Trace Logs
     Outside --allow-fs-write.
   * Fix CVE-2026-56848:
     A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()`
     to be called re-entrantly while `nghttp2_session_mem_recv()` is executing,
     resulting in a heap-use-after-free.
   * Fix CVE-2026-56850:
     A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array
     key collisions, allowing mutual TLS (mTLS) client identities to be
     reused across requests configured with different client certificates.
   * Fix CVE-2026-58039:
     A flaw in Node.js Permission Model enforcement allows process.report writes
     (and overwrites) files outside --allow-fs-write paths.
     This can lead to confidentiality impact or bypass of the intended
     security boundary under affected configurations
   * Fix CVE-2026-58043!
     A flaw in Node.js Permission Model enforcement can over-grant
     filesystem access across radix-tree prefix boundaries.
     Under `--permission`, an attacker who is granted access to one
     path can abuse boundary handling to read from or write to paths
     outside the intended filesystem allowlist.
   * Fix CVE-2026-58040:
     An incomplete fix has been identified in Node.js: HTTPS Agent
     TLS session reuse skips hostname verification across identity policies
     (incomplete fix of CVE-2026-48934).
Checksums-Sha1:
 0f80bfb3ff4d0a08129c6c91bcd002ce58303ac8 563952 libnode-dev_20.19.2+dfsg-1+deb13u3_i386.deb
 f7f858a233136389c06971c8eb198bc7f133671e 40416112 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_i386.deb
 ec6bdecb51e1f1527277be7ac5a9e48cb240da65 12224112 libnode115_20.19.2+dfsg-1+deb13u3_i386.deb
 a7202989e0b7c53baf2b9e9fb38fec2050e52911 2980 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_i386.deb
 99dffef6738ade37475b5cae4837163ee2c05ed7 11151 nodejs_20.19.2+dfsg-1+deb13u3_i386-buildd.buildinfo
 4145d264d62f2e5a9ace0ebc8a536aa58d74fb22 354784 nodejs_20.19.2+dfsg-1+deb13u3_i386.deb
Checksums-Sha256:
 550781c390986c1eaa1a7be1c8aa01b8a58c0c6acdadcb3173300e2d01c7643d 563952 libnode-dev_20.19.2+dfsg-1+deb13u3_i386.deb
 2065dcb1d4507a4f9c8238759ccb9f87c5750c0e063ba6f66cc26a5f9a677b35 40416112 libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_i386.deb
 43bad83c2554918fa322e300b2a326b4caa1a8692cbfed47947c7ed17b71692a 12224112 libnode115_20.19.2+dfsg-1+deb13u3_i386.deb
 381704d82b9f5d8c97406bd9de801d485a09e7061666d7900e49d119774a866f 2980 nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_i386.deb
 31de0e49adb0356360593ccd6b56c4e9deca691504e5d9ac77a3b81d90334eb5 11151 nodejs_20.19.2+dfsg-1+deb13u3_i386-buildd.buildinfo
 d01584c8b458df62081aad2516edd172021e6fe5eed23e6f3fbe7bee574d0b06 354784 nodejs_20.19.2+dfsg-1+deb13u3_i386.deb
Files:
 acbfab2860861a729e8c2835d0630cfe 563952 libdevel optional libnode-dev_20.19.2+dfsg-1+deb13u3_i386.deb
 2c8758621c52caf81143a842dec7d707 40416112 debug optional libnode115-dbgsym_20.19.2+dfsg-1+deb13u3_i386.deb
 04b3c897a79d82b7ec95ac926e86bc9a 12224112 libs optional libnode115_20.19.2+dfsg-1+deb13u3_i386.deb
 a42f86ac76f340a49d2e6a206c029d6b 2980 debug optional nodejs-dbgsym_20.19.2+dfsg-1+deb13u3_i386.deb
 a1ec7beb6987e1d2e43a8cc6eebffdb2 11151 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_i386-buildd.buildinfo
 e596370bde3c5c63c682dc21cccda233 354784 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_i386.deb

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE+i/sCsF3puL4e7qIGNGWmfrqILEFAmqzU00ACgkQGNGWmfrq
ILGr7g/8DWkOu417VakIji48rBTQpCKtrOjQLF879NK+4NdNb3ibNHsZ5X04S2+p
lxwU7PzzXznDuOveeJR94mdjEN9WgM8QbN4+NnEruWFjRfZxMpxBS+368bzIIhUH
02yfs2k79gge4QTnVSrQTXJAmagAFHFuAlxUEzdzwF9CajSg2ErOqjFW/2lkfQLq
Ynw9FuPve04eyv20WXiRtdkeeA0CyNpqMHqkS6qJU90avpdHX050CwxCRKkto2Mz
+IY87EbhESNtVABCpe8eBN8mRntlxelzc16r2WXUkUHtmK6nAbXRIehrM0FGdsDk
w2H2s13UX0UE+Ap+vXhkbn1AZG+oiIrUAAnP0TC4/MCYXPY4DAdh2VRLst+JsGF8
21srjATlUqP6mLslyR+Q7nkU17nhERMi2zATJiqiKI63oEisCiJiG3iNu8zco9rV
PtOQhXp6ol6Vgycd1QipPp7HGLA0G+TV5EOnkwLnujw9G51PM6oEb4VkkQl1pdg6
Yz49gycGmzIsJizyuye+zYimnlFC6EOeKUL75rW/HJqBlcaVXfx/1G3XS3loHEHI
P3hAVVZ6S+vWirVYMdjK9kAHXI+PVrVo08b7/HlQno4JdYeCMd2robuFxfqwEHIh
eRwfzlyWDqwSgiiKs0R5/lqCI9e7EbtpE013jDp/IX9jbda5Wqo=
=wsXI
-----END PGP SIGNATURE-----
