Multiple Vulnerabilities in SUSE Curl and Node.js Affect Security and Performance

Multiple Vulnerabilities in SUSE Curl and Node.js Affect Security and Performance

First seen 30 Jun 2026, 21:03 UTC Linuxsecurity 73% similarity 57.8
Share:

Article Content

Browse articles
ThreatCluster

SUSE has released updates addressing several vulnerabilities in Curl and Node.js, impacting various systems. The Curl update includes multiple CVEs, such as CVE-2026-6253, which allows proxy credential leaks, and CVE-2026-6429, exposing netrc credentials. Node.js vulnerabilities include CVE-2026-48619, which prevents unbounded memory growth, and CVE-2026-48615, which redacts proxy credentials in error messages. These vulnerabilities could lead to credential leaks and denial of service (DoS) attacks. Users of SUSE Linux Enterprise Server and Node.js are advised to apply the patches immediately. The updates were released on June 30, 2026, with varying severity ratings.

Key Points: • SUSE Curl and Node.js updates released on June 30, 2026, addressing multiple vulnerabilities. • Critical CVEs include Curl's CVE-2026-6253 and Node.js's CVE-2026-48619, which could lead to credential leaks. • Users are urged to apply patches immediately to mitigate potential security risks.

ThreatCluster AI

Timeline

2026-05-13
Multiple Curl vulnerabilities published
CVE-2026-5773, CVE-2026-6253, CVE-2026-4873, CVE-2026-6429 disclosed, affecting Curl's security.
Linuxsecurity
2026-05-13
CVE-2026-5773 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-13
CVE-2026-6253 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-13
CVE-2026-4873 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-13
CVE-2026-6276 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-13
CVE-2026-6429 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-05-13
CVE-2026-5545 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-17
Node.js vulnerability CVE-2026-11525 published
CVE-2026-11525 disclosed, affecting Node.js security and performance.
Linuxsecurity
2026-06-18
CVE-2026-48617 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-06-22
Node.js vulnerabilities CVE-2026-48931 published
CVE-2026-48931 disclosed, addressing response queue poisoning in Node.js.
Linuxsecurity

Community

Browse all →