-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Tue, 22 Sep 2026 19:12:18 +0200
Source: nodejs
Binary: nodejs-doc
Architecture: all
Version: 20.19.2+dfsg-1+deb13u3
Distribution: trixie-security
Urgency: medium
Maintainer: all Build Daemon (x86-grnet-02) <buildd_all-x86-grnet-02@buildd.debian.org>
Changed-By: Bastien Roucariès <rouca@debian.org>
Description:
 nodejs-doc - API documentation for Node.js, the javascript platform
Changes:
 nodejs (20.19.2+dfsg-1+deb13u3) trixie-security; urgency=medium
 .
   * Team upload
   * Fix CVE-2026-48617:
     A flaw in Node.js Permission Model enforcement allows Bypass
     via `process.report.writeReport()` Path Misvalidation.
     This can lead to confidentiality impact or bypass of the
     intended security boundary under affected configurations.
   * Fix CVE-2026-48618:
     A flaw in Node.js TLS hostname handling can cause Node.js unicode
     dot separator handling can lead to tls wildcard-depth
     authentication bypass due to resolver and verifier hostname
     normalization mismat. This can lead to confidentiality impact
     or bypass of the intended security boundary under
     affected configurations.
   * Fix CVE-2026-48619:
     A malicious HTTP/2 server can send repeated ORIGIN frames with unique
     origins, causing unbounded growth of the client-side originSet for the
     lifetime of the session. Cap the set at 128 entries; once full, new
     origins from ORIGIN frames are silently dropped.
   * Fix CVE-2026-48928: case-sensitive SNI context matching
     The regex constructed by server.addContext() lacked the case-insensitive
     flag, causing uppercase or mixed-case SNI hostnames from ClientHello to
     miss their intended context and fall back to the default context. This
     violates RFC 6066 Section 3, which states that DNS hostnames are
     case-insensitive. In mTLS configurations with per-tenant contexts, this
     allowed bypassing client certificate authorization by simply
     uppercasing the SNI hostname.
   * Fix CVE-2026-48930:
     A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames
     can lead to silent authority rebinding due to c-string truncation
     in resolver bindings.
   * Fix CVE-2026-48931:
     HTTP Agent can cause a client to accept as valid a response
     that is send before the client has sent the request.
   * Fix CVE-2026-48933:
     A flaw in Node.js WebCrypto implementation can crash the process
     if the input of `subtle.encrypt()` is a multiple of 2GiB.
   * Fix CVE-2026-48934:
     A flaw in Node.js TLS host verification can cause an attacker
     to bypass certification validation.
   * Fix CVE-2026-48935:
     A flaw in Node.js Permission API can cause a file metadata
     to be modified even on a path that was set as read-only
     with e.g. --allow-fs-read.
   * Fix CVE-2026-48937:
     A flaw in Node.js HTTP/2 server API can cause servers
     to keep accepting data even after sending a `GOAWAY` frame.
   * Fix CVE-2026-56846
     A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained
     header blocks evade maxSessionMemory
     and enable remote memory exhaustion.
   * Fix CVE-2026-56847:
     A flaw in Node.js Permission Model enforcement allows
     trace_events.createTracing().enable() Writes Trace Logs
     Outside --allow-fs-write.
   * Fix CVE-2026-56848:
     A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()`
     to be called re-entrantly while `nghttp2_session_mem_recv()` is executing,
     resulting in a heap-use-after-free.
   * Fix CVE-2026-56850:
     A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array
     key collisions, allowing mutual TLS (mTLS) client identities to be
     reused across requests configured with different client certificates.
   * Fix CVE-2026-58039:
     A flaw in Node.js Permission Model enforcement allows process.report writes
     (and overwrites) files outside --allow-fs-write paths.
     This can lead to confidentiality impact or bypass of the intended
     security boundary under affected configurations
   * Fix CVE-2026-58043!
     A flaw in Node.js Permission Model enforcement can over-grant
     filesystem access across radix-tree prefix boundaries.
     Under `--permission`, an attacker who is granted access to one
     path can abuse boundary handling to read from or write to paths
     outside the intended filesystem allowlist.
   * Fix CVE-2026-58040:
     An incomplete fix has been identified in Node.js: HTTPS Agent
     TLS session reuse skips hostname verification across identity policies
     (incomplete fix of CVE-2026-48934).
Checksums-Sha1:
 a71c8fc881301163fc009b515d0b1e7855ac19ea 6087656 nodejs-doc_20.19.2+dfsg-1+deb13u3_all.deb
 4e7fdcab812cc5158c0690c25d4281cf62e1ea4f 10215 nodejs_20.19.2+dfsg-1+deb13u3_all-buildd.buildinfo
Checksums-Sha256:
 330defda9cac8dde1a26d4bcba07f9789a4d65ba080fc9e1bdfb9b247010870e 6087656 nodejs-doc_20.19.2+dfsg-1+deb13u3_all.deb
 702ddca6ffc88f1fa5523ed2454fc94a01ab821e8e8fec05e7cf0cd35217a3a0 10215 nodejs_20.19.2+dfsg-1+deb13u3_all-buildd.buildinfo
Files:
 f80a319c257e091b33d7723c5757c46a 6087656 doc optional nodejs-doc_20.19.2+dfsg-1+deb13u3_all.deb
 e5b294f12c4857ba1253380127274be0 10215 javascript optional nodejs_20.19.2+dfsg-1+deb13u3_all-buildd.buildinfo

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE81O8NL+3kjBAqEvLmgPNRvTf/zcFAmqy95IACgkQmgPNRvTf
/zdCow/+NyYWZ2p5R206jNudV3MuosAAC97dPnzZ4rp3UOCN1RUk40N5a0unYZHO
vhvH7v+xuQIrhoz3icn/8hBBRLtw8lSJefTIOyZtEBvqBLCPf2BeBZ6eI+DWaw2l
0wcPwipwch/jvoJzzbeE7fp0t3TY2TWdZ4NOBKaQHjGpUpG5t5RD6L/8FqxdnSrv
V0xW936ZWGLmh/lmYHnbNUfC2r9Eo5aiVo4uvi3k14oemIW4KTmiyoF8RQbTTJmk
OpnDlcV6VJJXkCuJKzmtxlBdkww699nGUFLbAypRMmjrtGQElVUggJb63Rs3RTJr
atxiE1KTZl9fHdJ4qfWT9yxyizwlIBWnbpxmOGZXHogzIXnKGPxKSRPXKc7FMbCm
UU5QnkdHj1SuBdwNlfCbd2Ubo0yb4OL0GCa5lvgJ9jNMZXsQo6ctzJ/EIcUhSmKa
DK2v1DbFxT1R4hT6JCu/kjhXl8VmQyEv7IrihP9ZbIxGcrtcPZnL/TIYFdHoM5hC
OGD9ZaZMZZM1NmcdeFfDCpaL3ipwJSpghEoQqfQ26Vft2pJKaZtz1qXDRIul3Mwv
EjnHpw1jr3uTdbb6+Ugfh8KcJG+pnHHod8BbjCYYlHuSzcF8luiYQ467Y6Di1Doq
H/1InVF0FuFG+zFbHc4ur7bp7f+FUBuApnjZy1hCpbTM0ohdZRA=
=5BkU
-----END PGP SIGNATURE-----
