🛡️ SUSE-SU-2026:0295-1 — nodejs22 (CVE-2026-22036 +6 more)
Description
Security update for nodejs22
This update for nodejs22 fixes the following issues:
Security fixes:
- CVE-2026-22036: Fixed unbounded decompression chain in HTTP response leading
to resource exhaustion (bsc#1256848)
- CVE-2026-21637: Fixed synchronous exceptions thrown during callbacks that bypass
TLS error handling and causing denial of service (bsc#1256576)
- CVE-2025-55132: Fixed futimes() ability to acces file even if process has read
permissions only (bsc#1256571)
- CVE-2025-55131: Fixed race condition that allowed allocations with leftover data
leading to in-process secrets exposure (bsc#1256570)
- CVE-2025-55130: Fixed filesystem permissions bypass via crafted symlinks (bsc#1256569)
- CVE-2025-59465: Fixed malformed HTTP/2 HEADERS frame with invalid HPACK leading
to crash (bsc#1256573)
- CVE-2025-59466: Fixed uncatchable 'Maximum call stack size exceeded' error
leading to crash (bsc#1256574)
Other fixes:
- Update to 22.22.0:
- deps: updated undici to 6.23.0
- deps: updated bundled c-ares to 1.34.6 (if used)
- add TLSSocket default error handler
- disable futimes when permission model is enabled
- require full read and write to symlink APIs
- rethrow stack overflow exceptions in async_hooks
- refactor unsafe buffer creation to remove zero-fill toggle
- route callback exceptions through error handlers
- Update to 22.21.1:
- src: avoid unnecessary string -> char* -> string round trips
- src: remove unnecessary shadowed functions on Utf8Value & BufferValue
- process: fix hrtime fast call signatures
- http: improve writeEarlyHints by avoiding for-of loop
- Update to 22.21.0:
- cli: add --use-env-proxy
- http: support http proxy for fetch under NODE_USE_ENV_PROXY
- http: add shouldUpgradeCallback to let servers control HTTP upgrades
- http,https: add built-in proxy support in http/https.request and Agent
- src: add percentage support to --max-old-space-size
- Update to 22.20.0
- doc: stabilize --disable-sigusr1
- doc: mark path.matchesGlob as stable
- http: add Agent.agentKeepAliveTimeoutBuffer option
- http2: add support for raw header arrays in h2Stream.respond()
- inspector: add http2 tracking support
- sea: implement execArgvExtension
- sea: support execArgv in sea config
- stream: add brotli support to CompressionStream and DecompressionStream
- test_runner: support object property mocking
- worker: add cpu profile APIs for worker
- Update to 22.19.0
- cli: add NODE_USE_SYSTEM_CA=1
- cli: support ${pid} placeholder in --cpu-prof-name
- crypto: add tls.setDefaultCACertificates()
- dns: support max timeout
- doc: update the instruction on how to verify releases
- esm: unflag --experimental-wasm-modules
- http: add server.keepAliveTimeoutBuffer option
- lib: docs deprecate _http_*
- net: update net.blocklist to allow file save and file management
- process: add threadCpuUsage
- zlib: add dictionary support to zstdCompress and zstdDecompress
- Update to 22.18.0:
- deps: update amaro to 1.1.0
- doc: add all watch-mode related flags to node.1
- doc: add islandryu to collaborators
- esm: implement import.meta.main
- fs: allow correct handling of burst in fs-events with AsyncIterator
- permission: propagate permission model flags on spawn
- sqlite: add support for readBigInts option in db connection level
- src,permission: add support to permission.has(addon)
- url: add fileURLToPathBuffer API
- watch: add --watch-kill-signal flag
- worker: make Worker async disposable
Affected software
SUSE-SU-2026:0295-1 is recorded against 1 package.
- nodejs22 (fixed in 22.22.0-150600.13.12.1)
Timeline and source
Published on 26 January 2026 and last revised on 23 March 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
www.suse.com (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| nodejs22 | — | 22.22.0-150600.13.12.1 |
References
Similar Threats
- Unknown RHSA-2026:53298
- Unknown RHSA-2026:45381
- Unknown RHSA-2026:48305
- Unknown RHSA-2026:48033
- Unknown RHSA-2026:39246
Free Vulnerability Check
Is your site affected by SUSE-SU-2026:0295-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2026:0295-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.