Back Linuxsecurity SUSE Nodejs 24 Important Security Update for Multiple Issues 2026-3520
Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges ×
## This update for nodejs24 fixes the following issues: Update to 24.18.1. * CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust- boundary checks (bsc#1272882). * CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941). * CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949). * CVE-2026-56848: HTTP/2 re-entrant send can cause heap use-after-free (bsc#1272942). * CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944). * CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950). * CVE-2026-58040: HTTPS agent session reuse can skip hostname verification
## This update for nodejs24 fixes the following issues: Update to 24.18.1. * CVE-2026-54272: ip-address: misclassification of IPv4-mapped/NAT64 IPv6 addresses allows for bypass of SSRF and trust- boundary checks (bsc#1272882). * CVE-2026-56846: HTTP/2 retained headers can bypass `maxSessionMemory` limits (bsc#1272941). * CVE-2026-56847: permission model allows trace events to write outside the `allowlist` (bsc#1272949). * CVE-2026-56848: HTTP/2 re-entrant send can cause heap use-after-free (bsc#1272942). * CVE-2026-56850: HTTPS agent can reuse mTLS identities across PFX certificates (bsc#1272944). * CVE-2026-58039: permission model allows process reports to write outside the `allowlist` (bsc#1272950). * CVE-2026-58040: HTTPS agent session reuse can skip hostname verification
* CVE-2026-54272 ( SUSE ): 6.3
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
* CVE-2026-54272 ( SUSE ): 7.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
* CVE-2026-54272 ( NVD ): 6.9
Announcement ID: SUSE-SU-2026:3520-1 Release Date: 2026-08-06T11:31:17Z Rating: important
Get the latest Linux and open source security news straight to your inbox.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
