SUSE SLES12 Security Update : nodejs18 (SUSE-SU-2026:4248-1)

critical Nessus Plugin ID 347901

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES12 / SLES_SAP12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2026:4248-1 advisory.

- CVE-2025-22150: undici: insufficiently random values used when defining the boundary for a multipart/form-data request (bsc#1236258).
- CVE-2025-23166: improper error handling in async cryptographic operations crashes process (bsc#1243218).
- CVE-2025-23167: llhttp: improper HTTP header block termination in llhttp (bsc#1243220).
- CVE-2025-55131: timeout-based race conditions allow for allocations that contain leftover data from previous operations and lead to exposure of in-process secrets (bsc#1256570).
- CVE-2025-59465: malformed HTTP/2 HEADERS frame with invalid HPACK data can cause a crash due to an unhandled error (bsc#1256573).
- CVE-2025-59466: uncatchable 'Maximum call stack size exceeded' error when `async_hooks.createHook()` is enabled can lead to crash (bsc#1256574).
- CVE-2025-62408: c-ares 1.32.3-1.34.5 use after free() (bsc#1254738).
- CVE-2026-6733: undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery (bsc#1268479).
- CVE-2026-9679: undici: undici vulnerable to HTTP header injection via Set-Cookie percent-decoding (bsc#1268477).
- CVE-2026-11525: undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set- Cookie header (bsc#1268481).
- CVE-2026-12151: undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (bsc#1268482).
- CVE-2026-15157: No validation of the type property of a duck-typed blob-like request body before using it as the Content-Type header on the HTTP/1.1 dispatcher (bsc#1272958).
- CVE-2026-16728: undici: downstream response desynchronization via retry interceptor (bsc#1273593).
- CVE-2026-16729: undici: undici's setCookie function does not fully sanitize cookie attributes (bsc#1273591).
- CVE-2026-21637: synchronous exceptions thrown during certain callbacks bypass the standard TLS error handling paths and can cause a denial of service (bsc#1256576).
- CVE-2026-21710: uncaught TypeError exception can cause a denial of service (bsc#1260455).
- CVE-2026-21713: timing side-channel in HMAC verification via memcmp can lead to potential MAC forgery (bsc#1260463).
- CVE-2026-21714: WINDOW_UPDATE frames on stream 0 can lead to memory leak (bsc#1260480).
- CVE-2026-21717: crafted request can lead to hash collisions trivially predictable (bsc#1260494).
- CVE-2026-22036: undici: unbounded decompression chain in HTTP responses via Content-Encoding may lead to resource exhaustion (bsc#1256848).
- CVE-2026-27135: nghttp2: assertion failure due to missing state validation can lead to DoS (bsc#1259853).
- CVE-2026-48618: Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismatch (bsc#1268593).
- CVE-2026-48619: Unbounded memory growth in node:http2 clients via attacker-controlled ORIGIN frames (bsc#1268618).
- CVE-2026-48928: Uppercase sni context matching can lead to mtls authorization bypass due to case- sensitive hostname matching (bsc#1268605).
- CVE-2026-48930: Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings (bsc#1268606).
- CVE-2026-48931: HTTP Response Queue Poisoning via TOCTOU Race Condition in http.Agent (bsc#1268611).
- CVE-2026-48933: Node.js WebCrypto AES Integer Overflow Leads to Remote Process Abort (bsc#1268592).
- CVE-2026-48934: TLS host identity verification bypass via session reuse with different servername leads to unauthorized connections (bsc#1268608).
- CVE-2026-48935: Permission Model bypass via FileHandle.utimes() in the promises API (bsc#1268609).
- CVE-2026-48937: servers keep accepting data even after sending a `GOAWAY` frame (bsc#1268555).
- CVE-2026-56846: HTTP/2 retained headers can bypass maxSessionMemory limits (bsc#1272941).
- CVE-2026-56848: HTTP/2 re-entrant send can cause heap-use-after-free (bsc#1272942).
- CVE-2026-56850: HTTPS Agent can reuse mTLS identities across PFX certificates (bsc#1272944).
- CVE-2026-58040: HTTPS Agent session reuse can skip hostname verification (bsc#1272945).
- CVE-2026-58042: dns.resolveAny() can abort on DNS responses with many A records (bsc#1272947).
- CVE-2026-58043: Permission Model path matching can over-grant filesystem access (bsc#1272943).
- CVE-2026-58044: HTTP parser header truncation can enable request smuggling (bsc#1272951).
- CVE-2026-58045: node:zlib sync APIs can crash on spoofed TypedArray length (bsc#1272948).

Changes for nodejs18:

- upgraded embedded undici to 6.28.0.
- upgraded embedded nghttp2 to 1.69.0.

Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected nodejs18, nodejs18-devel, nodejs18-docs and / or npm18 packages.

See Also

https://bugzilla.suse.com/1236258

https://bugzilla.suse.com/1243218

https://bugzilla.suse.com/1243220

https://bugzilla.suse.com/1254738

https://bugzilla.suse.com/1256570

https://bugzilla.suse.com/1256573

https://bugzilla.suse.com/1256574

https://bugzilla.suse.com/1256576

https://bugzilla.suse.com/1256848

https://bugzilla.suse.com/1259853

https://bugzilla.suse.com/1260455

https://bugzilla.suse.com/1260463

https://bugzilla.suse.com/1260480

https://bugzilla.suse.com/1260494

https://bugzilla.suse.com/1268477

https://bugzilla.suse.com/1268479

https://bugzilla.suse.com/1268481

https://bugzilla.suse.com/1268482

https://bugzilla.suse.com/1268555

https://bugzilla.suse.com/1268592

https://bugzilla.suse.com/1268593

https://bugzilla.suse.com/1268605

https://bugzilla.suse.com/1268606

https://bugzilla.suse.com/1268608

https://bugzilla.suse.com/1268609

https://bugzilla.suse.com/1268611

https://bugzilla.suse.com/1268618

https://bugzilla.suse.com/1269825

https://bugzilla.suse.com/1272941

https://bugzilla.suse.com/1272942

https://bugzilla.suse.com/1272943

https://bugzilla.suse.com/1272944

https://bugzilla.suse.com/1272945

https://bugzilla.suse.com/1272947

https://bugzilla.suse.com/1272948

https://bugzilla.suse.com/1272951

https://bugzilla.suse.com/1272958

https://bugzilla.suse.com/1273591

https://bugzilla.suse.com/1273593

https://www.suse.com/security/cve/CVE-2025-22150

https://www.suse.com/security/cve/CVE-2025-23166

https://www.suse.com/security/cve/CVE-2025-23167

https://www.suse.com/security/cve/CVE-2025-55131

https://www.suse.com/security/cve/CVE-2025-59465

https://www.suse.com/security/cve/CVE-2025-59466

https://www.suse.com/security/cve/CVE-2025-62408

https://www.suse.com/security/cve/CVE-2026-11525

https://www.suse.com/security/cve/CVE-2026-12151

https://www.suse.com/security/cve/CVE-2026-15157

https://www.suse.com/security/cve/CVE-2026-16728

https://www.suse.com/security/cve/CVE-2026-16729

https://www.suse.com/security/cve/CVE-2026-21637

https://www.suse.com/security/cve/CVE-2026-21710

https://www.suse.com/security/cve/CVE-2026-21713

https://www.suse.com/security/cve/CVE-2026-21714

https://www.suse.com/security/cve/CVE-2026-21717

https://www.suse.com/security/cve/CVE-2026-22036

https://www.suse.com/security/cve/CVE-2026-27135

https://www.suse.com/security/cve/CVE-2026-48618

https://www.suse.com/security/cve/CVE-2026-48619

https://www.suse.com/security/cve/CVE-2026-48928

https://www.suse.com/security/cve/CVE-2026-48930

https://www.suse.com/security/cve/CVE-2026-48931

https://www.suse.com/security/cve/CVE-2026-48933

https://www.suse.com/security/cve/CVE-2026-48934

https://www.suse.com/security/cve/CVE-2026-48935

https://www.suse.com/security/cve/CVE-2026-48937

https://www.suse.com/security/cve/CVE-2026-56846

https://www.suse.com/security/cve/CVE-2026-56848

https://www.suse.com/security/cve/CVE-2026-56850

https://www.suse.com/security/cve/CVE-2026-58040

https://www.suse.com/security/cve/CVE-2026-58042

https://www.suse.com/security/cve/CVE-2026-58043

https://www.suse.com/security/cve/CVE-2026-58044

https://www.suse.com/security/cve/CVE-2026-58045

https://www.suse.com/security/cve/CVE-2026-6733

https://www.suse.com/security/cve/CVE-2026-9679

http://www.nessus.org/u?7e1b1f95

Plugin Details

Severity: Critical

ID: 347901

File Name: suse_SU-2026-4248-1.nasl

Version: 1.1

Type: Local

Agent: unix

Published: 9/18/2026

Updated: 9/18/2026

Supported Sensors: Nessus Agent, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.9

Percentile: 96.92

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2026-48930

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:novell:suse_linux:12, p-cpe:/a:novell:suse_linux:nodejs18-devel, p-cpe:/a:novell:suse_linux:nodejs18-docs, p-cpe:/a:novell:suse_linux:nodejs18, p-cpe:/a:novell:suse_linux:npm18

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/17/2026

Vulnerability Publication Date: 1/21/2025

Reference Information

CVE: CVE-2025-22150, CVE-2025-23166, CVE-2025-23167, CVE-2025-55131, CVE-2025-59465, CVE-2025-59466, CVE-2025-62408, CVE-2026-11525, CVE-2026-12151, CVE-2026-15157, CVE-2026-16728, CVE-2026-16729, CVE-2026-21637, CVE-2026-21710, CVE-2026-21713, CVE-2026-21714, CVE-2026-21717, CVE-2026-22036, CVE-2026-27135, CVE-2026-48618, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48931, CVE-2026-48933, CVE-2026-48934, CVE-2026-48935, CVE-2026-48937, CVE-2026-56846, CVE-2026-56848, CVE-2026-56850, CVE-2026-58040, CVE-2026-58042, CVE-2026-58043, CVE-2026-58044, CVE-2026-58045, CVE-2026-6733, CVE-2026-9679

SuSE: SUSE-SU-2026:4248-1