SUSE-SU-2026:1509-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20261509-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1509-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:1509-1
Upstream
CVE (7)
Related
Published
2026-04-21T06:27:53Z
Modified
2026-04-22T08:16:40Z
Summary
Security update for nodejs22
Details

This update for nodejs22 fixes the following issues:

Update to version 22.22.2.

  • CVE-2026-21717: trivially predictable hash collisions due to flaw in V8's string hashing mechanism allows for performance degradation via a crafted request (bsc#1260494).
  • CVE-2026-21716: incomplete fix for CVE-2024-36137 allows promise-based FileHandle methods to be used to modify file permissions and ownership on already-open file descriptors (bsc#1260462).
  • CVE-2026-21715: flaw in the Permission Model filesystem enforcement allows for file existence disclosure and filesystem path enumeration via fs.realpathSync.native() (bsc#1260482).
  • CVE-2026-21714: memory leak in Node.js HTTP/2 server allows for resource exhaustion via WINDOW_UPDATE frames sent on stream 0 (bsc#1260480).
  • CVE-2026-21713: timing side-channel due to flaw in Node.js HMAC verification allows for discovery of HMAC values and potential MAC forgery (bsc#1260463).
  • CVE-2026-21710: uncaught TypeError when handling HTTP requests allows for a process crash via requests with a header named __proto__ when the application accesses req.headersDistinct (bsc#1260455).
  • CVE-2026-21637: flaw in TLS error handling allows for resource exhaustion and crash when pskCallback or ALPNCallback are in use (bsc#1256576).
References

Affected packages

SUSE:Linux Enterprise Server 15 SP6-LTSS / nodejs22

Package

Name
nodejs22
Purl
pkg:rpm/suse/nodejs22&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP6-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
22.22.2-150600.13.15.1

Ecosystem specific

{
    "binaries":  [
        {
            "nodejs22":  "22.22.2-150600.13.15.1",
            "nodejs22-devel":  "22.22.2-150600.13.15.1",
            "nodejs22-docs":  "22.22.2-150600.13.15.1",
            "npm22":  "22.22.2-150600.13.15.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1509-1.json"

SUSE:Linux Enterprise Server for SAP Applications 15 SP6 / nodejs22

Package

Name
nodejs22
Purl
pkg:rpm/suse/nodejs22&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
22.22.2-150600.13.15.1

Ecosystem specific

{
    "binaries":  [
        {
            "nodejs22":  "22.22.2-150600.13.15.1",
            "nodejs22-devel":  "22.22.2-150600.13.15.1",
            "nodejs22-docs":  "22.22.2-150600.13.15.1",
            "npm22":  "22.22.2-150600.13.15.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1509-1.json"