Skip to content
Critical Security Flaws Found in SUSE Node.js Versions 22 and 24

Critical Security Flaws Found in SUSE Node.js Versions 22 and 24

First seen 7 Aug 2026, 08:28 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster August 8, 2026 at 08:07 UTC
  • SUSE issued security updates for Node.js versions 22 and 24 on August 6, 2026.
  • Multiple CVEs were addressed, including critical vulnerabilities allowing SSRF bypass and heap-use-after-free.
  • Administrators are urged to update to the latest versions to mitigate potential exploitation.

SUSE released important security updates for Node.js versions 22 and 24 on August 6, 2026, addressing multiple vulnerabilities. The updates include fixes for CVE-2026-54272, CVE-2026-56846, CVE-2026-56847, CVE-2026-56848, CVE-2026-56850, CVE-2026-58039, and CVE-2026-58040. These vulnerabilities could allow for SSRF bypass, heap-use-after-free, and unauthorized writing outside of permission models. Affected systems include those running Node.js versions 22.23.2 and 24.18.1. The vulnerabilities were published between July 27 and August 4, 2026, with CVE-2026-56846 and CVE-2026-56848 being particularly critical. Administrators are advised to apply the updates promptly to mitigate risks. The overall impact could be significant given the nature of the vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 45d ago How this analysis works

Timeline

2026-07-27
CVE-2026-54272 published
Vulnerability allows misclassification of IPv4-mapped/NAT64 IPv6 addresses, enabling SSRF bypass.
Linuxsecurity
2026-07-30
CVE-2026-56850 and CVE-2026-58040 published
Vulnerabilities allow mTLS identity reuse and session reuse skipping hostname verification.
Linuxsecurity
2026-07-30
CVE-2026-56847 published
Permission model flaw allows trace events to write outside the 'allowlist'.
Linuxsecurity
2026-07-31
CVE-2026-58039 published
Vulnerability permits process reports to write outside the 'allowlist'.
Linuxsecurity
2026-08-04
CVE-2026-56846 and CVE-2026-56848 published
Vulnerabilities allow HTTP/2 retained headers to bypass limits and cause heap-use-after-free.
Linuxsecurity
2026-08-06
SUSE releases updates for Node.js 22 and 24
Updates address multiple critical vulnerabilities, urging immediate application by administrators.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-54272 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed