Skip to content
openSUSE Nodejs20 Important Denial of Service Vulnern 2026-3929

openSUSE Nodejs20 Important Denial of Service Vulnern 2026-3929

Linuxsecurity LinuxSecurity Advisories September 3, 2026

Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×

This update for nodejs20 fixes the following issues:

* CVE-2025-22150: undici: predictable random values used when defining the

boundary for a `multipart`/`form-data` request (bsc#1236258).

* CVE-2026-6733: undici: response queue poisoning on reused keep-alive sockets

can lead to incorrect response delivery (bsc#1268479).

* CVE-2026-9496: pacote: excessive CPU consumption in `addGitSha` when

processing a specially crafted `spec.rawSpec` value can lead to DoS

* CVE-2026-9679: undici: HTTP header injection via `Set-Cookie` percent-

decoding (bsc#1268477).

* CVE-2026-11525: undici: weakening of cookie `SameSite` policy due to

incorrect parsing of `Set-Cookie` header (bsc#1268481).

* CVE-2026-12151: undici: denial of service due to unbounded memory growth via

WebSocket frames (bsc#1268482).

* CVE-2026-16728: undici: downstream response desynchronization via retry

interceptor (bsc#1273593).

* CVE-2026-16729: undici:...

## Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like

YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

* SUSE Linux Enterprise Server 15 SP6 LTSS

zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3929=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6

zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3929=1

zypper in -t patch SUSE-2026-3929=1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)

* nodejs20-docs-20.20.2-150600.3.21.1

* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)

* nodejs20-debugsource-20.20.2-150600.3.21.1

* nodejs20-debuginfo-20.20.2-150600.3.21.1

* nodejs20-devel-20.20.2-150600.3.21.1

* nodejs20-20.20.2-150600.3.21.1

* npm20-20.20.2-150600.3.21.1

* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)

* nodejs20-debugsource-20.20.2-150600.3.21.1

* nodejs20-debuginfo-20.20.2-150600.3.21.1

* nodejs20-devel-20.20.2-150600.3.21.1

* nodejs20-20.20.2-150600.3.21.1

* npm20-20.20.2-150600.3.21.1

* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)

* nodejs20-docs-20.20.2-150600.3.21.1

* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)

* nodejs20-debugsource-20.20.2-150600.3.21.1

* nodejs20-debuginfo-20.20.2-150600.3.21.1

* nodejs20-devel-20.20.2-150600.3.21.1

* nodejs20-20.20.2-150600.3.21.1

* npm20-20.20.2-150600.3.21.1

* corepack20-20.20.2-150600.3.21.1

*

*

*

*

*

*

*

*

*

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases