Back Linuxsecurity SUSE Nodejs20 Important Security Update for 35 Vulnerabilities 2026-3930
Keep your Linux systems secure and up to date with practical patching guidance. Review Linux Patching Best Practices ×
## This update for nodejs20 fixes the following issues: * CVE-2025-22150: undici: predictable random values used when defining the boundary for a `multipart`/`form-data` request (bsc#1236258). * CVE-2026-6733: undici: response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (bsc#1268479). * CVE-2026-9496: pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec` value can lead to DoS (bsc#1266318). * CVE-2026-9679: undici: HTTP header injection via `Set-Cookie` percent- decoding (bsc#1268477). * CVE-2026-11525: undici: weakening of cookie `SameSite` policy due to incorrect parsing of `Set-Cookie` header (bsc#1268481). * CVE-2026-12151: undici: denial of service due to unbounded memory growth via
## This update for nodejs20 fixes the following issues: * CVE-2025-22150: undici: predictable random values used when defining the boundary for a `multipart`/`form-data` request (bsc#1236258). * CVE-2026-6733: undici: response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (bsc#1268479). * CVE-2026-9496: pacote: excessive CPU consumption in `addGitSha` when processing a specially crafted `spec.rawSpec` value can lead to DoS (bsc#1266318). * CVE-2026-9679: undici: HTTP header injection via `Set-Cookie` percent- decoding (bsc#1268477). * CVE-2026-11525: undici: weakening of cookie `SameSite` policy due to incorrect parsing of `Set-Cookie` header (bsc#1268481). * CVE-2026-12151: undici: denial of service due to unbounded memory growth via
Announcement ID: SUSE-SU-2026:3930-1 Release Date: 2026-09-03T07:19:03Z Rating: important
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
