SUSE-CU-2026:8623-1: Security update of bci/nodejs
sle-container-updates at lists.suse.com
sle-container-updates at lists.suse.com
Wed Aug 12 07:59:00 UTC 2026
SUSE Container Update Advisory: bci/nodejs
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:8623-1
Container Tags : bci/node:22 , bci/node:22-sles15 , bci/node:22.23.2 , bci/node:22.23.2-24.28 , bci/nodejs:22 , bci/nodejs:22-sles15 , bci/nodejs:22.23.2 , bci/nodejs:22.23.2-24.28
Container Release : 24.28
Severity : important
Type : security
References : 1272882 1272941 1272942 1272943 1272944 1272945 1272947 1272948
1272949 1272950 1272951 CVE-2026-54272 CVE-2026-56846 CVE-2026-56847
CVE-2026-56848 CVE-2026-56850 CVE-2026-58039 CVE-2026-58040 CVE-2026-58042
CVE-2026-58043 CVE-2026-58044 CVE-2026-58045
-----------------------------------------------------------------
The container bci/nodejs was updated. The following patches have been included in this update:
-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3557-1
Released: Mon Aug 10 19:59:13 2026
Summary: Security update for nodejs22
Type: security
Severity: important
References: 1272882,1272941,1272942,1272943,1272944,1272945,1272947,1272948,1272949,1272950,1272951,CVE-2026-54272,CVE-2026-56846,CVE-2026-56847,CVE-2026-56848,CVE-2026-56850,CVE-2026-58039,CVE-2026-58040,CVE-2026-58042,CVE-2026-58043,CVE-2026-58044,CVE-2026-58045
This update for nodejs22 fixes the following issues:
Update to 22.23.2.
- CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust-
boundary checks (bsc#1272882).
- CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941).
- CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949).
- CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942).
- CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944).
- CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950).
- CVE-2026-58040: HTTPS agent session reuse can skip hostname verification (bsc#1272945).
- CVE-2026-58042: `dns.resolveAny()` can abort on DNS responses with many A records (bsc#1272947).
- CVE-2026-58043: permission model path matching can over-grant filesystem access (bsc#1272943).
- CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951).
- CVE-2026-58045: `node:zlib` sync APIs can crash on spoofed `TypedArray` length (bsc#1272948).
The following package changes have been done:
- nodejs22-22.23.2-150700.3.18.1 updated
- npm22-22.23.2-150700.3.18.1 updated
More information about the sle-container-updates
mailing list