- nodejs (18.20.4+dfsg-1~deb12u2+rpi1) bookworm-staging; urgency=medium
++nodejs (18.20.4+dfsg-1~deb12u3+rpi1) bookworm-staging; urgency=medium
+
+ [changes brought forward from 18.10.0+dfsg-6+rpi1 by Peter Michael Green <plugwash@raspbian.org> at Tue, 15 Nov 2022 03:51:54 +0000]
+ * Set --with-arm-version=6 on raspbian.
+ * Use armv6k CFLAGS on raspbian.
+ * Disable testsuite.
+
- -- Raspbian forward porter <root@raspbian.org> Tue, 19 May 2026 00:07:39 +0000
++ -- Raspbian forward porter <root@raspbian.org> Thu, 01 Oct 2026 23:20:35 +0000
++
+ nodejs (18.20.4+dfsg-1~deb12u3) bookworm-security; urgency=high
+
+ * Team upload
+ * Fix CVE-2026-48618:
+ A flaw in Node.js TLS hostname handling can cause Node.js
+ unicode dot separator handling can lead to tls wildcard-depth
+ authentication bypass due to resolver and verifier hostname
+ normalization mismatch
+ * Fix CVE-2026-48618:
+ A flaw in Node.js TLS hostname handling can cause Node.js unicode
+ dot separator handling can lead to tls wildcard-depth
+ authentication bypass due to resolver and verifier hostname
+ normalization mismat. This can lead to confidentiality impact
+ or bypass of the intended security boundary under
+ affected configurations.
+ * Fix CVE-2026-48928: case-sensitive SNI context matching
+ The regex constructed by server.addContext() lacked the case-insensitive
+ flag, causing uppercase or mixed-case SNI hostnames from ClientHello to
+ miss their intended context and fall back to the default context. This
+ violates RFC 6066 Section 3, which states that DNS hostnames are
+ case-insensitive. In mTLS configurations with per-tenant contexts, this
+ allowed bypassing client certificate authorization by simply
+ uppercasing the SNI hostname.
+ * Fix CVE-2026-48930:
+ A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames
+ can lead to silent authority rebinding due to c-string truncation
+ in resolver bindings.
+ * Fix CVE-2026-48931:
+ HTTP Agent can cause a client to accept as valid a response
+ that is send before the client has sent the request.
+ * Fix CVE-2026-48933:
+ A flaw in Node.js WebCrypto implementation can crash the process
+ if the input of `subtle.encrypt()` is a multiple of 2GiB.
+ * Fix CVE-2026-48934:
+ A flaw in Node.js TLS host verification can cause an attacker
+ to bypass certification validation.
+ * Fix CVE-2026-56846
+ A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained
+ header blocks evade maxSessionMemory
+ and enable remote memory exhaustion.
+ * Fix CVE-2026-56848:
+ A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()`
+ to be called re-entrantly while `nghttp2_session_mem_recv()` is executing,
+ resulting in a heap-use-after-free.
+ * Fix CVE-2026-56850:
+ A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array
+ key collisions, allowing mutual TLS (mTLS) client identities to be
+ reused across requests configured with different client certificates.
+ * Fix CVE-2026-58042:
+ A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process
+ When a DNS Response Contains More Than 256 A Records.
+ Repeated triggering of this condition can lead to denial of service.
+ * Fix CVE-2026-58040:
+ An incomplete fix has been identified in Node.js:
+ HTTPS Agent TLS session reuse skips hostname verification across
+ identity policies (incomplete fix of CVE-2026-48934).
+ * Fix FTBFS due to openssl changes
+
+ -- Bastien Roucariès <rouca@debian.org> Sun, 16 Aug 2026 19:34:06 +0200
nodejs (18.20.4+dfsg-1~deb12u2) bookworm-security; urgency=medium