]> dgit.raspbian.org Git - nodejs.git/log
nodejs.git
6 weeks agosrc: fix error handling on async crypto operations
RafaelGSS [Mon, 12 May 2025 15:33:54 +0000 (12:33 -0300)]
src: fix error handling on async crypto operations

Fixes: https://hackerone.com/reports/2817648
Co-Authored-By: Filip Skokan <panva.ip@gmail.com>
Co-Authored-By: Tobias Nießen <tniessen@tnie.de>
Backport-PR-URL: https://github.com/nodejs-private/node-private/pull/688
CVE-ID: CVE-2025-23166
PR-URL: https://github.com/nodejs-private/node-private/pull/710

origin: backport, https://github.com/nodejs/node/commit/6c57465920cf1b981a63031e71b1e4a73bf9beaa

Gbp-Pq: Name CVE-2025-23166.patch

6 weeks agosrc: fix HTTP2 mem leak on premature close and ERR_PROTO
RafaelGSS [Tue, 17 Dec 2024 19:58:03 +0000 (16:58 -0300)]
src: fix HTTP2 mem leak on premature close and ERR_PROTO

This commit fixes a memory leak when the socket is
suddenly closed by the peer (without GOAWAY notification)
and when invalid header (by nghttp2) is identified and the
connection is terminated by peer.

Refs: https://hackerone.com/reports/2841362
PR-URL: https://github.com/nodejs-private/node-private/pull/650
Reviewed-By: James M Snell <jasnell@gmail.com>
CVE-ID: CVE-2025-23085
origin: https://github.com/nodejs/node/commit/6cc8d58e6f97c37c228f134bd9b98246c8871fb1

Gbp-Pq: Name CVE-2025-23085.patch

6 weeks agosrc: rethrow stack overflow exceptions in async_hooks When a stack overflow exception...
Matteo Collina [Sun, 26 Apr 2026 15:21:57 +0000 (17:21 +0200)]
src: rethrow stack overflow exceptions in async_hooks When a stack overflow exception occurs during async_hooks callbacks (which use TryCatchScope::kFatal), detect the specific "Maximum call stack size exceeded" RangeError and re-throw it instead of immediately calling FatalException. This allows user code to catch the exception with try-catch blocks instead of requiring uncaughtException handlers.

The implementation adds IsStackOverflowError() helper to detect stack
overflow RangeErrors and re-throws them in TryCatchScope destructor
instead of calling FatalException.

This fixes the issue where async_hooks would cause stack overflow
exceptions to exit with code 7 (kExceptionInFatalExceptionHandler)
instead of being catchable.

Fixes: #37989
Ref: https://hackerone.com/reports/3456295
PR-URL: nodejs-private/node-private#773
Refs: https://hackerone.com/reports/3456295
Reviewed-By: Robert Nagy <ronagy@icloud.com>
Reviewed-By: Paolo Insogna <paolo@cowtech.it>
Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Anna Henningsen <anna@addaleax.net>
CVE-ID: CVE-2025-59466
origin: backport, https://github.com/nodejs/node/commit/d7a5c587c02ebe18f9fe4de986bac55d80c2868f
bug: https://nodejs.org/en/blog/vulnerability/december-2025-security-releases#uncatchable-maximum-call-stack-size-exceeded-error-on-nodejs-via-async_hooks-leads-to-process-crashes-bypassing-error-handlers-cve-2025-59466---medium

Gbp-Pq: Name CVE-2025-59466.patch

6 weeks agolib: add TLSSocket default error handler
RafaelGSS [Fri, 31 Oct 2025 19:27:48 +0000 (16:27 -0300)]
lib: add TLSSocket default error handler

This prevents the server from crashing due to an unhandled rejection
when a TLSSocket connection is abruptly destroyed during initialization
and the user has not attached an error handler to the socket.
e.g:

```js
const server = http2.createSecureServer({ ... })
server.on('secureConnection', socket => {
  socket.on('error', err => {
    console.log(err)
  })
})
```

PR-URL: https://github.com/nodejs-private/node-private/pull/797
Fixes: https://github.com/nodejs/node/issues/44751
Refs: https://hackerone.com/bugs?subject=nodejs&report_id=3262404
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Anna Henningsen <anna@addaleax.net>
CVE-ID: CVE-2025-59465

Gbp-Pq: Name CVE-2025-59465.patch

6 weeks agosrc,lib: refactor unsafe buffer creation to remove zero-fill toggle
ChALkeR Nikita Skovoroda [Mon, 6 Apr 2026 14:13:34 +0000 (16:13 +0200)]
src,lib: refactor unsafe buffer creation to remove zero-fill toggle

This removes the zero-fill toggle mechanism that allowed JavaScript
to control ArrayBuffer initialization via shared memory. Instead,
unsafe buffer creation now uses a dedicated C++ API.

Refs: https://hackerone.com/reports/3405778
Co-Authored-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Co-Authored-By: Joyee Cheung <joyeec9h3@gmail.com>
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: https://github.com/nodejs-private/node-private/pull/759
Backport-PR-URL: https://github.com/nodejs-private/node-private/pull/799
CVE-ID: CVE-2025-55131

origin: backport, https://github.com/nodejs/node/commit/51f4de4b4a52b5b0eb2c63ecbb4126577e05f636

Gbp-Pq: Name CVE-2025-55131.patch

6 weeks agoFix CVE-2024-24806
Debian Javascript Maintainers [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
Fix CVE-2024-24806

Bug: https://github.com/libuv/libuv/security/advisories/GHSA-f74f-cvh7-c6q6
Bug-Debian: https://bugs.debian.org/1063484
Origin: https://github.com/libuv/libuv
 git diff v1.48.0~5..v1.48.0~2

From upstream change log:
   Merge pull request from GHSA-f74f-cvh7-c6q6
    * fix: always zero-terminate idna output
    * fix: reject zero-length idna inputs
    * test: empty strings are not valid IDNA

See also https://github.com/libuv/libuv/security/advisories/GHSA-f74f-cvh7-c6q6
===================================================================

Gbp-Pq: Topic libuv
Gbp-Pq: Name fix-cve-2024-24806

6 weeks agofix undefined path_max for st_size zero
Mauricio Faria de Oliveira [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
fix undefined path_max for st_size zero

Bug-Ubuntu: https://bugs.launchpad.net/bugs/1792647
Bug-Debian: https://bugs.debian.org/909011
Reviewed-by: dod
The downstream 'path_max' patch in Debian sets the buffer size
for readlink() to the 'st_size' value obtained with lstat().

However, it might be zero for some symlinks in /proc on Linux
(notably /proc/self) leading to readlink() failing with EINVAL.

    $ strace -e lstat stat /proc/self 2>&1 \
        | grep -e lstat -e File: -e Size:
    lstat("/proc/self", {st_mode=S_IFLNK|0777, st_size=0, ...}) = 0
      File: /proc/self -> 30875
      Size: 0             Blocks: 0          IO Block: 1024   symbolic link

This causes readlink (tool) to files like /dev/stdin to fail,
which may link to /proc/self/fd/0 on containers or elsewhere.

Test-case:

    ubuntu@cosmic:~/node$
    $ strace -E LD_LIBRARY_PATH=/usr/local/lib/ -f -e lstat,readlink \
      node test/parallel/test-fs-realpath-pipe.js

With path_max:

    [pid 17785] lstat("/dev", {st_mode=S_IFDIR|0755, st_size=480, ...}) = 0
    [pid 17786] lstat("/dev/stdin", {st_mode=S_IFLNK|0777, st_size=15, ...}) = 0
    [pid 17788] lstat("/dev/stdin", {st_mode=S_IFLNK|0777, st_size=15, ...}) = 0
    [pid 17788] readlink("/dev/stdin", "/proc/self/fd/0", 15) = 15

    [pid 17785] lstat("/proc", {st_mode=S_IFDIR|0555, st_size=0, ...}) = 0
    [pid 17786] lstat("/proc/self", {st_mode=S_IFLNK|0777, st_size=0, ...}) = 0
    [pid 17788] lstat("/proc/self", {st_mode=S_IFLNK|0777, st_size=0, ...}) = 0
    [pid 17788] readlink("/proc/self", 0x7f2a6c000b40, 0) = -1 EINVAL (Invalid argument)

Without path_max:

    [pid 18114] lstat("/dev", {st_mode=S_IFDIR|0755, st_size=480, ...}) = 0
    [pid 18114] lstat("/dev/stdin", {st_mode=S_IFLNK|0777, st_size=15, ...}) = 0
    [pid 18114] readlink("/dev/stdin", "/proc/self/fd/0", 4096) = 15

    [pid 18114] lstat("/proc", {st_mode=S_IFDIR|0555, st_size=0, ...}) = 0
    [pid 18114] lstat("/proc/self", {st_mode=S_IFLNK|0777, st_size=0, ...}) = 0
    [pid 18114] readlink("/proc/self", "18114", 4096) = 5

    [pid 18114] lstat("/proc/18114", {st_mode=S_IFDIR|0555, st_size=0, ...}) = 0
    [pid 18114] lstat("/proc/18114/fd", {st_mode=S_IFDIR|0500, st_size=0, ...}) = 0
    [pid 18114] lstat("/proc/18114/fd/0", {st_mode=S_IFLNK|0700, st_size=64, ...}) = 0
    [pid 18114] readlink("/proc/18114/fd/0", "socket:[199607]", 4096) = 15

With this patch on top of path_max:

    [pid 18433] lstat("/dev", {st_mode=S_IFDIR|0755, st_size=480, ...}) = 0
    [pid 18433] lstat("/dev/stdin", {st_mode=S_IFLNK|0777, st_size=15, ...}) = 0
    [pid 18433] lstat("/dev/stdin", {st_mode=S_IFLNK|0777, st_size=15, ...}) = 0
    [pid 18433] readlink("/dev/stdin", "/proc/self/fd/0", 15) = 15

    [pid 18433] lstat("/proc", {st_mode=S_IFDIR|0555, st_size=0, ...}) = 0
    [pid 18433] lstat("/proc/self", {st_mode=S_IFLNK|0777, st_size=0, ...}) = 0
    [pid 18433] lstat("/proc/self", {st_mode=S_IFLNK|0777, st_size=0, ...}) = 0
    [pid 18433] readlink("/proc/self", "18433", 256) = 5

    [pid 18433] lstat("/proc/18433", {st_mode=S_IFDIR|0555, st_size=0, ...}) = 0
    [pid 18433] lstat("/proc/18433/fd", {st_mode=S_IFDIR|0500, st_size=0, ...}) = 0
    [pid 18433] lstat("/proc/18433/fd/0", {st_mode=S_IFLNK|0700, st_size=64, ...}) = 0
    [pid 18433] lstat("/proc/18433/fd/0", {st_mode=S_IFLNK|0700, st_size=64, ...}) = 0
    [pid 18433] readlink("/proc/18433/fd/0", "socket:[191351]", 64) = 15
Reviewed-by: dod
Gbp-Pq: Topic libuv
Gbp-Pq: Name path_max_zero_st_size

6 weeks agoGet libuv nodejs in sync with libuv/bookworm
Bastien Roucariès [Sun, 27 Apr 2025 13:42:15 +0000 (15:42 +0200)]
Get libuv nodejs in sync with libuv/bookworm

forwarded: not-needed

Gbp-Pq: Topic libuv
Gbp-Pq: Name 0000-bookworm-sync.patch

6 weeks agoopenssl 3.0.14 returns a different code.
Debian Javascript Maintainers [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
openssl 3.0.14 returns a different code.

Forwarded: not-needed

Gbp-Pq: Topic build
Gbp-Pq: Name openssl_3014.patch

6 weeks agosome tests fail on mips64el and mipsel
Debian Javascript Maintainers [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
some tests fail on mips64el and mipsel

Forwarded: not-needed

That architecture support improves over time - node 20.x branch has better support for mips64el
Meanwhile, let those tests fail.

Gbp-Pq: Topic mips
Gbp-Pq: Name flaky_tests.patch

6 weeks agotest runner output fails on some cwd - fix regexp
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
test runner output fails on some cwd - fix regexp

Last-Update: 2023-11-30
Forwarded: https://github.com/nodejs/node/pull/50980

Gbp-Pq: Topic build
Gbp-Pq: Name test_runner_escape_path.patch

6 weeks agodisable test because it depends on postject, which is dfsg-excluded
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
disable test because it depends on postject, which is dfsg-excluded

Last-Update: 2023-11-30
Forwarded: not-needed

HELP is welcome to solve this

Gbp-Pq: Topic build
Gbp-Pq: Name disable_sea_dfsg_postject.patch

6 weeks agobuild using ada upstream tarball component
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
build using ada upstream tarball component

Last-Update: 2023-11-30
Forwarded: not-needed

Gbp-Pq: Topic build
Gbp-Pq: Name ada.patch

6 weeks agoHarmonize V8 stack sizes on ARM architectures to match almost all other architectures
James Addison [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
Harmonize V8 stack sizes on ARM architectures to match almost all other architectures

Last-Update: 2023-02-28
Forwarded: https://github.com/nodejs/node/issues/41163

Gbp-Pq: Topic arm64
Gbp-Pq: Name stacksize.patch

6 weeks agoUse system paths for builtins
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
Use system paths for builtins

Last-Update: 2023-02-22
Forwarded: not-needed

Gbp-Pq: Topic build
Gbp-Pq: Name test_process_versions.patch

6 weeks agofix link to home in html api
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
fix link to home in html api

Forwarded: not needed, in conflict with the meaning of home page
Last-Update: 06-11-2022

Gbp-Pq: Topic build
Gbp-Pq: Name doc_template_home.html

6 weeks agoallow vfp2 and allow setting arm_version option
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
allow vfp2 and allow setting arm_version option

Last-Update: 2022-08-29
Forwarded: https://github.com/nodejs/node/issues/44357

Gbp-Pq: Topic armel
Gbp-Pq: Name configure.patch

6 weeks agotest does not pass on riscv64
Jérémy Lal kapouer@melix.org, Bo YU [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
test does not pass on riscv64

Last-Update: 2022-12-14
Forwarded: not-yet

Gbp-Pq: Topic riscv
Gbp-Pq: Name flaky_tests.patch

6 weeks agoskip buffer NaN internal representation check this fails on whatever archs having...
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
skip buffer NaN internal representation check this fails on whatever archs having other internal representations of NaN.

Last-Update: 2022-05-02
Forwarded: https://github.com/nodejs/node/issues/42945

Gbp-Pq: Topic build
Gbp-Pq: Name skip-buffer-nan-internal-check.patch

6 weeks agofix double register usage on mipsel
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
fix double register usage on mipsel

Forwarded: not-yet
Last-Update: 2022-06-15

Gbp-Pq: Topic mips
Gbp-Pq: Name mipsel_even_register_fix.patch

6 weeks agomipsel in debian supports 32-bit processors
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
mipsel in debian supports 32-bit processors

Forwarded: not-needed
Last-Update: 2021-11-03

Gbp-Pq: Topic mips
Gbp-Pq: Name mipsel_is_32.patch

6 weeks agomksnapshot uses too much memory on 32-bit mipsel
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
mksnapshot uses too much memory on 32-bit mipsel

Last-Update: 2020-06-03
Forwarded: https://bugs.chromium.org/p/v8/issues/detail?id=10586

Gbp-Pq: Topic mips
Gbp-Pq: Name less_mem.patch

6 weeks agouse configuration directive to set mips fpu mode
YunQiang Su [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
use configuration directive to set mips fpu mode

Forwarded: https://github.com/paul99/v8m-rb/issues/192
Last-Update: 2015-09-29

Gbp-Pq: Topic mips
Gbp-Pq: Name fpu.patch

6 weeks agofix compilation error on mipsel target
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
fix compilation error on mipsel target

Last-Update: 2021-10-28
Forwarded: https://github.com/nodejs/node/issues/40624

Gbp-Pq: Topic mips
Gbp-Pq: Name compilation_error.patch

6 weeks agoremove google font from template.html, and link to local
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
remove google font from template.html, and link to local

Last-Update: 2015-09-09
Forwarded: not-needed

Gbp-Pq: Topic dfsg
Gbp-Pq: Name privacy_breach.patch

6 weeks agoMultiarch search path, arch triplet, DFHS path for modules
Bastien ROUCARIÈS [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
Multiarch search path, arch triplet, DFHS path for modules

Last-Update: 2018-09-30
Last-Update: 2020-03-04
Forwarded: https://github.com/nodejs/node/issues/22745
Reviewed-By: Xavier Guimard <yadd@debian.org>
Gbp-Pq: Topic dfsg
Gbp-Pq: Name multilib_modules.patch

6 weeks agoa test uses a benchmark that read alice.html, dfsg excluded
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
a test uses a benchmark that read alice.html, dfsg excluded

Forwarded: not-needed
Reviewed-By: Xavier Guimard <yadd@debian.org>
Last-Update: 2020-03-04

Gbp-Pq: Topic dfsg
Gbp-Pq: Name benchmark_without_alice.patch

6 weeks agouse system-installed node-gyp for building test modules
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
use system-installed node-gyp for building test modules

Last-Update: 2015-09-09
Forwarded: not-needed

Gbp-Pq: Topic deps
Gbp-Pq: Name node_gyp.patch

6 weeks agodo not use dns.ADDRCONFIG for localhost
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
do not use dns.ADDRCONFIG for localhost

Last-Update: 2020-06-11
Bug-Debian: https://bugs.debian.org/962318
Forwarded: https://github.com/nodejs/node/issues/33816

it fails on IPv6-only systems. Setting it with libc fails on linux.
https://github.com/nodejs/node/issues/33279

Gbp-Pq: Topic deps
Gbp-Pq: Name localhost-no-addrconfig.patch

6 weeks agokeep nodejs compatible with libc-ares public headers
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
keep nodejs compatible with libc-ares public headers

Forwarded: not-needed
Last-Update: 2021-10-20

Gbp-Pq: Topic deps
Gbp-Pq: Name cares.patch

6 weeks agoadapt test-ci build target for buildd
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
adapt test-ci build target for buildd

Forwarded: not-needed
Reviewed-By: Xavier Guimard <yadd@debian.org>
Last-Update: 2020-02-09

* run tests with ./node
* remove addons from test-ci suite, because it creates a dependency loop
  nodejs -> node-gyp -> nodejs which is painful to manage.
* disabled because it requires stdin:
  + test-stdout-close-unref
  + test-regress-GH-746
* test-tick-processor fails on ppc64 and s390x, currently investigated
  https://github.com/nodejs/node/issues/2471
* test-cluster-disconnect sometimes fails on busy buildd, forwarded upstream
  https://github.com/nodejs/node/issues/3383
* test-fs-watch is flaky, might be related to https://github.com/nodejs/node/issues/4082
* huge timeout value for all platforms, buildd could be busy
* test-npm-install and test-release-npm must fail, debian package dfsg-repacked npm out
* ability to override CI_NATIVE_SUITES, CI_JS_SUITES
* disable tests failing because DNS is disabled
* sequential/test-http2-session-timeout is flaky https://github.com/nodejs/node/issues/20628

Gbp-Pq: Topic build
Gbp-Pq: Name test_ci.patch

6 weeks agoLink to -latomic by default
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
Link to -latomic by default

Last-Update: 2019-10-25
Forwarded: not-needed
Bug: https://github.com/nodejs/node/pull/28532
Bug: https://github.com/nodejs/node/issues/30093

This avoids surprises on mips*el/ppc*el

Gbp-Pq: Topic build
Gbp-Pq: Name flag_atomic.patch

6 weeks agobuild doc using marked and js-yaml
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
build doc using marked and js-yaml

Forwarded: not-needed
Reviewed-By: Xavier Guimard <yadd@debian.org>
Last-Update: 2021-03-03

While waiting for unified/remarked/rehyped modules to be available in debian

Gbp-Pq: Topic build
Gbp-Pq: Name doc.patch

6 weeks agodo not build cctest, build broken on debian
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
do not build cctest, build broken on debian

Last-Update: 2017-12-18
Forwarded: not yet !

Gbp-Pq: Topic build
Gbp-Pq: Name cctest_disable.patch

6 weeks agoadd acorn, walk to shared builtins
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
add acorn, walk to shared builtins

Last-Update: 2022-09-28
Forwarded: https://github.com/nodejs/node/pull/44376

Gbp-Pq: Topic build
Gbp-Pq: Name more_shareable_builtins.patch

6 weeks agodebian openssl in testing or sid (3.0.11, 3.1.4) does not seem to have that different...
Jérémy Lal [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
debian openssl in testing or sid (3.0.11, 3.1.4) does not seem to have that different behavior

Last-Update: 2023-11-03

Gbp-Pq: Topic build
Gbp-Pq: Name openssl_3011_without_new_error_message.patch

6 weeks ago[PATCH] Add a CipherString for nodejs
Sebastian Andrzej Siewior [Fri, 23 Sep 2022 20:39:50 +0000 (22:39 +0200)]
[PATCH] Add a CipherString for nodejs

If the default security level is overwritten at build time of openssl
then it is needed to lower it again for nodejs in order to pass the
testsuite because it is using smoil keys.

Signed-off-by: Sebastian Andrzej Siewior <sebastian@breakpoint.cc>
Gbp-Pq: Topic build
Gbp-Pq: Name openssl_config_explicit_lower.patch

6 weeks agonodejs (18.20.4+dfsg-1~deb12u3) bookworm-security; urgency=high
Bastien Roucariès [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
nodejs (18.20.4+dfsg-1~deb12u3) bookworm-security; urgency=high

  * Team upload
  * Fix CVE-2026-48618:
    A flaw in Node.js TLS hostname handling can cause Node.js
    unicode dot separator handling can lead to tls wildcard-depth
    authentication bypass due to resolver and verifier hostname
    normalization mismatch
  * Fix CVE-2026-48618:
    A flaw in Node.js TLS hostname handling can cause Node.js unicode
    dot separator handling can lead to tls wildcard-depth
    authentication bypass due to resolver and verifier hostname
    normalization mismat. This can lead to confidentiality impact
    or bypass of the intended security boundary under
    affected configurations.
  * Fix CVE-2026-48928: case-sensitive SNI context matching
    The regex constructed by server.addContext() lacked the case-insensitive
    flag, causing uppercase or mixed-case SNI hostnames from ClientHello to
    miss their intended context and fall back to the default context. This
    violates RFC 6066 Section 3, which states that DNS hostnames are
    case-insensitive. In mTLS configurations with per-tenant contexts, this
    allowed bypassing client certificate authorization by simply
    uppercasing the SNI hostname.
  * Fix CVE-2026-48930:
    A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames
    can lead to silent authority rebinding due to c-string truncation
    in resolver bindings.
  * Fix CVE-2026-48931:
    HTTP Agent can cause a client to accept as valid a response
    that is send before the client has sent the request.
  * Fix CVE-2026-48933:
    A flaw in Node.js WebCrypto implementation can crash the process
    if the input of `subtle.encrypt()` is a multiple of 2GiB.
  * Fix CVE-2026-48934:
    A flaw in Node.js TLS host verification can cause an attacker
    to bypass certification validation.
  * Fix CVE-2026-56846
    A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained
    header blocks evade maxSessionMemory
    and enable remote memory exhaustion.
  * Fix CVE-2026-56848:
    A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()`
    to be called re-entrantly while `nghttp2_session_mem_recv()` is executing,
    resulting in a heap-use-after-free.
  * Fix CVE-2026-56850:
    A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array
    key collisions, allowing mutual TLS (mTLS) client identities to be
    reused across requests configured with different client certificates.
  * Fix CVE-2026-58042:
    A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process
    When a DNS Response Contains More Than 256 A Records.
    Repeated triggering of this condition can lead to denial of service.
  * Fix CVE-2026-58040:
    An incomplete fix has been identified in Node.js:
    HTTPS Agent TLS session reuse skips hostname verification across
    identity policies (incomplete fix of CVE-2026-48934).
  * Fix FTBFS due to openssl changes

[dgit import unpatched nodejs 18.20.4+dfsg-1~deb12u3]

6 weeks agoImport nodejs_18.20.4+dfsg-1~deb12u3.debian.tar.xz
Bastien Roucariès [Sun, 16 Aug 2026 17:34:06 +0000 (19:34 +0200)]
Import nodejs_18.20.4+dfsg-1~deb12u3.debian.tar.xz

[dgit import tarball nodejs 18.20.4+dfsg-1~deb12u3 nodejs_18.20.4+dfsg-1~deb12u3.debian.tar.xz]

2 years agoImport nodejs_18.20.4+dfsg.orig.tar.xz
Jérémy Lal [Tue, 9 Jul 2024 15:36:33 +0000 (17:36 +0200)]
Import nodejs_18.20.4+dfsg.orig.tar.xz

[dgit import orig nodejs_18.20.4+dfsg.orig.tar.xz]

2 years agoImport nodejs_18.20.4+dfsg.orig-ada.tar.xz
Jérémy Lal [Tue, 9 Jul 2024 15:36:33 +0000 (17:36 +0200)]
Import nodejs_18.20.4+dfsg.orig-ada.tar.xz

[dgit import orig nodejs_18.20.4+dfsg.orig-ada.tar.xz]

2 years agoImport nodejs_18.20.4+dfsg.orig-types-node.tar.xz
Jérémy Lal [Tue, 9 Jul 2024 15:36:33 +0000 (17:36 +0200)]
Import nodejs_18.20.4+dfsg.orig-types-node.tar.xz

[dgit import orig nodejs_18.20.4+dfsg.orig-types-node.tar.xz]