Opened 2 months ago

Closed 2 months ago

#23658 closed enhancement (fixed)

node.js-24.18.1

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: high Milestone: 98-Security
Component: BOOK Version: git
Severity: high Keywords:
Cc:

Description

New point version.

Change History (4)

comment:1 by Joe Locash, 2 months ago

Priority: normal → high
Severity: normal → high

​https://nodejs.org/en/blog/release/v24.18.1

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

This is a security release.

Notable Changes

  • (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High
  • (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
  • (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
  • (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
  • (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
  • (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
  • (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
  • (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
  • (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
  • (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
  • (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
  • deps: update llhttp to 9.4.3 (Paolo Insogna)
  • deps: update undici to 7.29.0 (Node.js GitHub Bot)

comment:2 by Joe Locash, 2 months ago

Owner: changed from blfs-book to Joe Locash
Status: new → assigned

comment:3 by Joe Locash, 2 months ago

Milestone: 13.1 → 98-Security
Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

Fixed at 41fbc3bf08. Leaving open for SA.

comment:4 by Bruce Dubbs, 2 months ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-187 has been released.

Note: See TracTickets for help on using tickets.