Linuxsecurity
Critical DoS Vulnerabilities in openSUSE Nodejs20
Article Content
Multiple denial of service (DoS) vulnerabilities have been identified in the openSUSE Nodejs20 package. The vulnerabilities include CVE-2026-9496, which can cause excessive CPU consumption, and CVE-2026-12151, leading to unbounded memory growth via WebSocket frames. Other issues involve predictable random values in multipart requests and HTTP header injection. These vulnerabilities affect various SUSE Linux Enterprise and openSUSE Leap versions. Administrators are urged to apply the patches immediately to mitigate risks. The vulnerabilities were disclosed on 2026-09-03, with some CVEs dating back to 2025. The advisory provides specific patch instructions for affected systems.
Key Points: • Multiple critical DoS vulnerabilities identified in openSUSE Nodejs20. • Affected systems include SUSE Linux Enterprise and openSUSE Leap. • Immediate patching is recommended to mitigate risks.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.