Linuxsecurity Critical Security Flaws Found in SUSE Node.js Versions 22 and 24
Article Content
- •SUSE issued security updates for Node.js versions 22 and 24 on August 6, 2026.
- •Multiple CVEs were addressed, including critical vulnerabilities allowing SSRF bypass and heap-use-after-free.
- •Administrators are urged to update to the latest versions to mitigate potential exploitation.
SUSE released important security updates for Node.js versions 22 and 24 on August 6, 2026, addressing multiple vulnerabilities. The updates include fixes for CVE-2026-54272, CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-56850, CVE-2026-58039, and CVE-2026-58040. These vulnerabilities could allow for SSRF bypass, heap-use-after-free, and unauthorized writing outside of permission models. Affected systems include those running Node.js versions 22.23.2 and 24.18.1. The vulnerabilities were published between July 27 and August 4, 2026, with CVE-2026-56846 and CVE-2026-56848 being particularly critical. Administrators are advised to apply the updates promptly to mitigate risks. The overall impact could be significant given the nature of the vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-54272 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Plugin4Shell: Zero-Click RCE Vulnerability in Major AI Coding Agents Plugin4Shell is a critical zero-click remote code execution vulnerability affecting four major AI coding agents: Claude Code, Codex, GitHub Copilot, and Gemini CLI. Discovered by AIR Security, this flaw allows attackers to exploit trusted plugin marketplaces by swapping legitimate plugins with malicious ones, gaining…
SSRF Vulnerability in Sentry MCP Server Exposes Security Risks On July 12, 2026, researcher cccccccti disclosed a Server-Side Request Forgery (SSRF) vulnerability in the raw_sentry_api component of ddfourtwo/sentry-selfhosted-mcp, tracked as CVE-2026-81421. This vulnerability allows attackers to force Axios to call arbitrary endpoints, with a public exploit already available. As…