Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

openSUSE 15.6 Nodejs24 Security Advisory SUSE-2026-0820-1

suse
Calendar Grey January 26, 2026
Dist Suse Esm H88
Critical update for nodejs22 on openSUSE addressing important security flaws to enhance system integrity.
An update that solves seven vulnerabilities can now be installed.

Summary

## This update for nodejs22 fixes the following issues: Security fixes: * CVE-2026-22036: Fixed unbounded decompression chain in HTTP response leading to resource exhaustion (bsc#1256848) * CVE-2026-21637: Fixed synchronous exceptions thrown during callbacks that bypass TLS error handling and causing denial of service (bsc#1256576) * CVE-2025-55132: Fixed futimes() ability to acces file even if process has read permissions only (bsc#1256571) * CVE-2025-55131: Fixed race condition that allowed allocations with leftover data leading to in-process secrets exposure (bsc#1256570) * CVE-2025-55130: Fixed filesystem permissions bypass via crafted symlinks (bsc#1256569) * CVE-2025-59465: Fixed malformed HTTP/2 HEADERS frame with invalid HPACK leading to crash (bsc#1256573)

References

* bsc#1256569

* bsc#1256570

* bsc#1256571

* bsc#1256573

* bsc#1256574

* bsc#1256576

* bsc#1256848

Cross-

* CVE-2025-55130

* CVE-2025-55131

* CVE-2025-55132

* CVE-2025-59465

* CVE-2025-59466

* CVE-2026-21637

* CVE-2026-22036

CVSS scores:

* CVE-2025-55130 ( SUSE ): 9.2

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

* CVE-2025-55130 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2025-55130 ( NVD ): 7.1 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

* CVE-2025-55131 ( SUSE ): 9.2

CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

* CVE-2025-55131 ( SUSE ): 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

* CVE-2025-55131 ( NVD ): 7.1 CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L

* CVE-2025-55132 ( SUSE ): 6.3

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:0295-1
Release Date: 2026-01-26T13:19:07Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here