•  
      request #47762 Node: 22.23.0 -> 22.23.2
    Infos
    #47762
    Thomas Gerbet (tgerbet)
    2026-07-30 09:05
    2026-07-30 08:17
    49507
    Details
    Node: 22.23.0 -> 22.23.2

    Security release

    (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High
    (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
    (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
    (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
    (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
    (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
    (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
    (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
    (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
    (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
    deps: update llhttp to 9.4.3 (Paolo Insogna)
    deps: update undici to 6.28.0 (Node.js GitHub Bot)
    
    Other
    All
    Empty
    • [ ] enhancement
    • [ ] internal improvement
    Empty
    Stage
    Thomas Gerbet (tgerbet)
    Closed
    2026-07-30
    Attachments
    Empty
    References
    Referenced by request #47762

    Follow-ups