Matteo Collina [Sun, 29 Mar 2026 15:42:54 +0000 (17:42 +0200)]
http: fix response queue poisoning in http.Agent
Attach a data guard listener on idle keepAlive sockets in the
freeSockets pool. If unsolicited data arrives while the socket
is idle, destroy it immediately to prevent response queue poisoning.
Refs: https://hackerone.com/reports/3582376
PR-URL: https://github.com/nodejs-private/node-private/pull/846 Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
CVE-ID: CVE-2026-48931
origin: https://github.com/nodejs/node/commit/0a22d40180cb796e0d68e94c1a7a8a05a8f47c10
bug: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases#http-response-queue-poisoning-via-toctou-race-condition-in-httpagent-cve-2026-48931---low
Gbp-Pq: Topic sec
Gbp-Pq: Name CVE-2026-48931.patch
The regex constructed by server.addContext() lacked the case-insensitive
flag, causing uppercase or mixed-case SNI hostnames from ClientHello to
miss their intended context and fall back to the default context. This
violates RFC 6066 Section 3, which states that DNS hostnames are
case-insensitive. In mTLS configurations with per-tenant contexts, this
allowed bypassing client certificate authorization by simply
uppercasing the SNI hostname.
Add the 'i' flag to the RegExp in addContext() so that SNI matching
is case-insensitive.
PR-URL: https://github.com/nodejs-private/node-private/pull/857 Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
CVE-ID: CVE-2026-48928
Refs: https://hackerone.com/reports/3656869
origin: backport, https://github.com/nodejs/node/commit/39d1d0968471a144d93dc293d640008f57d3c58e
Gbp-Pq: Topic sec
Gbp-Pq: Name CVE-2026-48928.patch
http2: cap originSet size to prevent unbounded memory growth
A malicious HTTP/2 server can send repeated ORIGIN frames with unique
origins, causing unbounded growth of the client-side originSet for the
lifetime of the session. Cap the set at 128 entries; once full, new
origins from ORIGIN frames are silently dropped.
Ref: https://hackerone.com/reports/3676863
PR-URL: https://github.com/nodejs-private/node-private/pull/855 Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
CVE-ID: CVE-2026-48619
Refs: https://hackerone.com/reports/3676863
origin: backport, https://github.com/nodejs/node/commit/c79968e108002c2394bdb9e9cefb2c8c8cc202f8
Gbp-Pq: Topic sec
Gbp-Pq: Name CVE-2026-48619.patch
Matteo Collina [Thu, 19 Feb 2026 14:49:43 +0000 (15:49 +0100)]
http: use null prototype for headersDistinct/trailersDistinct
Use { __proto__: null } instead of {} when initializing the
headersDistinct and trailersDistinct destination objects.
A plain {} inherits from Object.prototype, so when a __proto__
header is received, dest["__proto__"] resolves to Object.prototype
(truthy), causing _addHeaderLineDistinct to call .push() on it,
which throws an uncaught TypeError and crashes the process.
Ref: https://hackerone.com/reports/3560402
PR-URL: https://github.com/nodejs-private/node-private/pull/821
Refs: https://hackerone.com/reports/3560402 Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com> Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
CVE-ID: CVE-2026-21710
origin: https://github.com/nodejs/node/commit/00ad47a28eb2e3dc0ff5610d58c53341acf3cf8d
Matteo Collina [Tue, 17 Feb 2026 13:26:17 +0000 (14:26 +0100)]
tls: wrap SNICallback invocation in try/catch
Wrap the owner._SNICallback() invocation in loadSNI() with try/catch
to route exceptions through owner.destroy() instead of letting them
become uncaught exceptions. This completes the fix from CVE-2026-21637
which added try/catch protection to callALPNCallback,
onPskServerCallback, and onPskClientCallback but missed loadSNI().
Without this fix, a remote unauthenticated attacker can crash any
Node.js TLS server whose SNICallback may throw on unexpected input
by sending a single TLS ClientHello with a crafted server_name value.
Matteo Collina [Mon, 22 Dec 2025 17:25:33 +0000 (18:25 +0100)]
tls: route callback exceptions through error handlers
Wrap pskCallback and ALPNCallback invocations in try-catch blocks
to route exceptions through owner.destroy() instead of letting them
become uncaught exceptions. This prevents remote attackers from
crashing TLS servers or causing resource exhaustion.
RafaelGSS [Tue, 17 Dec 2024 19:58:03 +0000 (16:58 -0300)]
src: fix HTTP2 mem leak on premature close and ERR_PROTO
This commit fixes a memory leak when the socket is
suddenly closed by the peer (without GOAWAY notification)
and when invalid header (by nghttp2) is identified and the
connection is terminated by peer.
Refs: https://hackerone.com/reports/2841362
PR-URL: https://github.com/nodejs-private/node-private/pull/650 Reviewed-By: James M Snell <jasnell@gmail.com>
CVE-ID: CVE-2025-23085
origin: https://github.com/nodejs/node/commit/6cc8d58e6f97c37c228f134bd9b98246c8871fb1
src: rethrow stack overflow exceptions in async_hooks When a stack overflow exception occurs during async_hooks callbacks (which use TryCatchScope::kFatal), detect the specific "Maximum call stack size exceeded" RangeError and re-throw it instead of immediately calling FatalException. This allows user code to catch the exception with try-catch blocks instead of requiring uncaughtException handlers.
The implementation adds IsStackOverflowError() helper to detect stack
overflow RangeErrors and re-throws them in TryCatchScope destructor
instead of calling FatalException.
This fixes the issue where async_hooks would cause stack overflow
exceptions to exit with code 7 (kExceptionInFatalExceptionHandler)
instead of being catchable.
Fixes: #37989
Ref: https://hackerone.com/reports/3456295
PR-URL: nodejs-private/node-private#773
Refs: https://hackerone.com/reports/3456295 Reviewed-By: Robert Nagy <ronagy@icloud.com> Reviewed-By: Paolo Insogna <paolo@cowtech.it> Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com> Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com> Reviewed-By: Anna Henningsen <anna@addaleax.net>
CVE-ID: CVE-2025-59466
origin: backport, https://github.com/nodejs/node/commit/d7a5c587c02ebe18f9fe4de986bac55d80c2868f
bug: https://nodejs.org/en/blog/vulnerability/december-2025-security-releases#uncatchable-maximum-call-stack-size-exceeded-error-on-nodejs-via-async_hooks-leads-to-process-crashes-bypassing-error-handlers-cve-2025-59466---medium
RafaelGSS [Fri, 31 Oct 2025 19:27:48 +0000 (16:27 -0300)]
lib: add TLSSocket default error handler
This prevents the server from crashing due to an unhandled rejection
when a TLSSocket connection is abruptly destroyed during initialization
and the user has not attached an error handler to the socket.
e.g:
src,lib: refactor unsafe buffer creation to remove zero-fill toggle
This removes the zero-fill toggle mechanism that allowed JavaScript
to control ArrayBuffer initialization via shared memory. Instead,
unsafe buffer creation now uses a dedicated C++ API.
Bug-Ubuntu: https://bugs.launchpad.net/bugs/1792647
Bug-Debian: https://bugs.debian.org/909011 Reviewed-by: dod
The downstream 'path_max' patch in Debian sets the buffer size
for readlink() to the 'st_size' value obtained with lstat().
However, it might be zero for some symlinks in /proc on Linux
(notably /proc/self) leading to readlink() failing with EINVAL.
* run tests with ./node
* remove addons from test-ci suite, because it creates a dependency loop
nodejs -> node-gyp -> nodejs which is painful to manage.
* disabled because it requires stdin:
+ test-stdout-close-unref
+ test-regress-GH-746
* test-tick-processor fails on ppc64 and s390x, currently investigated
https://github.com/nodejs/node/issues/2471
* test-cluster-disconnect sometimes fails on busy buildd, forwarded upstream
https://github.com/nodejs/node/issues/3383
* test-fs-watch is flaky, might be related to https://github.com/nodejs/node/issues/4082
* huge timeout value for all platforms, buildd could be busy
* test-npm-install and test-release-npm must fail, debian package dfsg-repacked npm out
* ability to override CI_NATIVE_SUITES, CI_JS_SUITES
* disable tests failing because DNS is disabled
* sequential/test-http2-session-timeout is flaky https://github.com/nodejs/node/issues/20628
If the default security level is overwritten at build time of openssl
then it is needed to lower it again for nodejs in order to pass the
testsuite because it is using smoil keys.
Signed-off-by: Sebastian Andrzej Siewior <sebastian@breakpoint.cc>
Gbp-Pq: Topic build
Gbp-Pq: Name openssl_config_explicit_lower.patch
* Team upload
* Fix CVE-2026-48618:
A flaw in Node.js TLS hostname handling can cause Node.js
unicode dot separator handling can lead to tls wildcard-depth
authentication bypass due to resolver and verifier hostname
normalization mismatch
* Fix CVE-2026-48618:
A flaw in Node.js TLS hostname handling can cause Node.js unicode
dot separator handling can lead to tls wildcard-depth
authentication bypass due to resolver and verifier hostname
normalization mismat. This can lead to confidentiality impact
or bypass of the intended security boundary under
affected configurations.
* Fix CVE-2026-48928: case-sensitive SNI context matching
The regex constructed by server.addContext() lacked the case-insensitive
flag, causing uppercase or mixed-case SNI hostnames from ClientHello to
miss their intended context and fall back to the default context. This
violates RFC 6066 Section 3, which states that DNS hostnames are
case-insensitive. In mTLS configurations with per-tenant contexts, this
allowed bypassing client certificate authorization by simply
uppercasing the SNI hostname.
* Fix CVE-2026-48930:
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames
can lead to silent authority rebinding due to c-string truncation
in resolver bindings.
* Fix CVE-2026-48931:
HTTP Agent can cause a client to accept as valid a response
that is send before the client has sent the request.
* Fix CVE-2026-48933:
A flaw in Node.js WebCrypto implementation can crash the process
if the input of `subtle.encrypt()` is a multiple of 2GiB.
* Fix CVE-2026-48934:
A flaw in Node.js TLS host verification can cause an attacker
to bypass certification validation.
* Fix CVE-2026-56846
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained
header blocks evade maxSessionMemory
and enable remote memory exhaustion.
* Fix CVE-2026-56848:
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()`
to be called re-entrantly while `nghttp2_session_mem_recv()` is executing,
resulting in a heap-use-after-free.
* Fix CVE-2026-56850:
A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array
key collisions, allowing mutual TLS (mTLS) client identities to be
reused across requests configured with different client certificates.
* Fix CVE-2026-58042:
A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process
When a DNS Response Contains More Than 256 A Records.
Repeated triggering of this condition can lead to denial of service.
* Fix CVE-2026-58040:
An incomplete fix has been identified in Node.js:
HTTPS Agent TLS session reuse skips hostname verification across
identity policies (incomplete fix of CVE-2026-48934).
* Fix FTBFS due to openssl changes