nodejs (24.19.0+dfsg+~cs24.13.3-1)
[PTS] [DDPO]
OK: VCS matches the version in the archive
- Git: https://salsa.debian.org/js-team/nodejs.git -b debian/24.x
-
- Branch: debian/24.x
- Path: debian/changelog
- Repo size: 6008832
- Browser: https://salsa.debian.org/js-team/nodejs/tree/debian/24.x
- Last scan: 2026-08-08 20:47:04+00
- Error: https://salsa.debian.org/api/v4/projects/js-team%2Fnodejs API request failed: 401 Unauthorized at /srv/qa.debian.org/data/vcswatch/vcswatch line 410.
- Next scan: 2026-08-16 10:00:00+00
- Debian changelog in Git:
nodejs (24.19.0+dfsg+~cs24.13.3-1) unstable; urgency=medium
* New upstream version 24.19.0+dfsg+~cs24.13.3
This release addresses the following vulnerabilities:
+ CVE-2026-58042: dns: handle large resolveAny address replies
+ CVE-2026-58044: http: reject requests exceeding max header count
+ CVE-2026-56848: http2: defer rst stream while in scope
+ CVE-2026-56846: http2: retain header memory in session accounting
+ CVE-2026-58040: https: bind identity checks to session reuse
+ CVE-2026-56850: https: distinguish PFX object-array agent keys
+ CVE-2026-58043: permission: avoid granting radix split nodes
+ CVE-2026-58039: permission: check final report output path
+ CVE-2026-56847: permission: enforce fs write permission for trace events
+ CVE-2026-58041: sqlite: invalidate tag store iterators on statement reset
+ CVE-2026-58045: zlib: throw on out-of-bounds write buffers
* Refresh doc generator, fix links
* Skip another typescript test
-- Jérémy Lal <kapouer@melix.org> Sat, 08 Aug 2026 15:01:44 +0200
- This branch is even with tag debian/24.19.0+dfsg+_cs24.13.3-1