Updated nodejs packages fix security vulnerabilities
Publication date: 01 Sep 2026Modification date: 01 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-56846 , CVE-2026-56848 , CVE-2026-58043 , CVE-2026-56850 , CVE-2026-58040 , CVE-2026-58042 , CVE-2026-58045 , CVE-2026-56847 , CVE-2026-58039 , CVE-2026-58044
Description
http2: retain header memory in session accounting. (CVE-2026-56846)
http2: defer rst stream while in scope. (CVE-2026-56848)
permission: avoid granting radix split nodes. (CVE-2026-58043)
https: distinguish PFX object-array agent keys. (CVE-2026-56850)
https: bind identity checks to session reuse. (CVE-2026-58040)
dns: handle large resolveAny address replies. (CVE-2026-58042)
zlib: throw on out-of-bounds write buffers. (CVE-2026-58045)
permission: enforce fs write permission for trace events.
(CVE-2026-56847)
permission: check final report output path. (CVE-2026-58039)
http: reject requests exceeding max header count. (CVE-2026-58044)
References
- https://bugs.mageia.org/show_bug.cgi?id=36201
- https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
- https://nodejs.org/en/blog/release/v22.23.2
- https://www.cve.org/CVERecord?id=CVE-2026-56846
- https://www.cve.org/CVERecord?id=CVE-2026-56848
- https://www.cve.org/CVERecord?id=CVE-2026-58043
- https://www.cve.org/CVERecord?id=CVE-2026-56850
- https://www.cve.org/CVERecord?id=CVE-2026-58040
- https://www.cve.org/CVERecord?id=CVE-2026-58042
- https://www.cve.org/CVERecord?id=CVE-2026-58045
- https://www.cve.org/CVERecord?id=CVE-2026-56847
- https://www.cve.org/CVERecord?id=CVE-2026-58039
- https://www.cve.org/CVERecord?id=CVE-2026-58044
SRPMS
10/core
- nodejs-22.23.2-1.mga10
9/core
- nodejs-22.23.2-1.mga9