Back Linuxsecurity openSUSE Nodejs20 Important Denial of Service Vulnern 2026-3929
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
This update for nodejs20 fixes the following issues:
* CVE-2025-22150: undici: predictable random values used when defining the
boundary for a `multipart`/`form-data` request (bsc#1236258).
* CVE-2026-6733: undici: response queue poisoning on reused keep-alive sockets
can lead to incorrect response delivery (bsc#1268479).
* CVE-2026-9496: pacote: excessive CPU consumption in `addGitSha` when
processing a specially crafted `spec.rawSpec` value can lead to DoS
* CVE-2026-9679: undici: HTTP header injection via `Set-Cookie` percent-
decoding (bsc#1268477).
* CVE-2026-11525: undici: weakening of cookie `SameSite` policy due to
incorrect parsing of `Set-Cookie` header (bsc#1268481).
* CVE-2026-12151: undici: denial of service due to unbounded memory growth via
WebSocket frames (bsc#1268482).
* CVE-2026-16728: undici: downstream response desynchronization via retry
interceptor (bsc#1273593).
* CVE-2026-16729: undici:...
## Patch Instructions:
To install this SUSE update use the SUSE recommended installation methods like
YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
* SUSE Linux Enterprise Server 15 SP6 LTSS
zypper in -t patch SUSE-SLE-Product-SLES-15-SP6-LTSS-2026-3929=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6
zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-SP6-2026-3929=1
zypper in -t patch SUSE-2026-3929=1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (noarch)
* nodejs20-docs-20.20.2-150600.3.21.1
* SUSE Linux Enterprise Server for SAP Applications 15 SP6 (ppc64le x86_64)
* nodejs20-debugsource-20.20.2-150600.3.21.1
* nodejs20-debuginfo-20.20.2-150600.3.21.1
* nodejs20-devel-20.20.2-150600.3.21.1
* nodejs20-20.20.2-150600.3.21.1
* npm20-20.20.2-150600.3.21.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (aarch64 ppc64le s390x x86_64)
* nodejs20-debugsource-20.20.2-150600.3.21.1
* nodejs20-debuginfo-20.20.2-150600.3.21.1
* nodejs20-devel-20.20.2-150600.3.21.1
* nodejs20-20.20.2-150600.3.21.1
* npm20-20.20.2-150600.3.21.1
* SUSE Linux Enterprise Server 15 SP6 LTSS (noarch)
* nodejs20-docs-20.20.2-150600.3.21.1
* openSUSE Leap 15.6 (aarch64 i586 ppc64le s390x x86_64)
* nodejs20-debugsource-20.20.2-150600.3.21.1
* nodejs20-debuginfo-20.20.2-150600.3.21.1
* nodejs20-devel-20.20.2-150600.3.21.1
* nodejs20-20.20.2-150600.3.21.1
* npm20-20.20.2-150600.3.21.1
* corepack20-20.20.2-150600.3.21.1
*
*
*
*
*
*
*
*
*
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
