{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* SECURITY UPDATE: HTTP/2 client ORIGIN-frame unbounded memory growth\n     - debian/patches/CVE-2026-48619.patch: cap the client-side originSet\n       (maxOriginSetSize, default 128) in lib/internal/http2/core.js and\n       destroy the session with ERR_HTTP2_TOO_MANY_ORIGINS\n     - CVE-2026-48619\n   * SECURITY UPDATE: embedded-NUL hostnames cause silent authority rebinding\n     - debian/patches/CVE-2026-48930.patch: add validateStringWithoutNullBytes\n       in lib/internal/validators.js and reject embedded-NUL hostnames in\n       lib/dns.js, lib/internal/dns/promises.js and lib/net.js\n     - CVE-2026-48930\n   * SECURITY UPDATE: WebCrypto cipher output-length integer overflow\n     - debian/patches/CVE-2026-48933.patch: add TryGetIntCipherOutputLength\n       in src/crypto/crypto_cipher.h and guard the AES_Cipher output length\n       in src/crypto/crypto_aes.cc against signed int overflow\n     - CVE-2026-48933",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197",
        "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_alt_nodejs/debian11/advisories/2026/clsa-2026_1783422197.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-29T15:40:51Z",
      "generator": {
        "date": "2026-07-29T15:40:51Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1783422197",
      "initial_release_date": "2026-07-07T11:04:26Z",
      "revision_history": [
        {
          "date": "2026-07-07T11:04:26Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-29T15:40:51Z",
          "number": "2",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "Fix CVE(s): CVE-2026-48619, CVE-2026-48930, CVE-2026-48933"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 11",
                "product": {
                  "name": "Debian 11",
                  "product_id": "Debian-11",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:11:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
                "product": {
                  "name": "alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
                  "product_id": "alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-nodejs20-nodejs-devel@20.20.2-3?arch=amd64&os_name=debian&os_version=11"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64",
                "product": {
                  "name": "alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64",
                  "product_id": "alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-nodejs20-npm@10.8.2-20.20.2-3?arch=amd64&os_name=debian&os_version=11"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs20-docs-0:20.20.2-3.amd64",
                "product": {
                  "name": "alt-nodejs20-docs-0:20.20.2-3.amd64",
                  "product_id": "alt-nodejs20-docs-0:20.20.2-3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-nodejs20-docs@20.20.2-3?arch=amd64&os_name=debian&os_version=11"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs20-nodejs-0:20.20.2-3.amd64",
                "product": {
                  "name": "alt-nodejs20-nodejs-0:20.20.2-3.amd64",
                  "product_id": "alt-nodejs20-nodejs-0:20.20.2-3.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-nodejs20-nodejs@20.20.2-3?arch=amd64&os_name=debian&os_version=11"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
                "product": {
                  "name": "alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
                  "product_id": "alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-nodejs20-nodejs-devel@20.20.2-2?arch=amd64&os_name=debian&os_version=11"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs20-docs-0:20.20.2-2.amd64",
                "product": {
                  "name": "alt-nodejs20-docs-0:20.20.2-2.amd64",
                  "product_id": "alt-nodejs20-docs-0:20.20.2-2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-nodejs20-docs@20.20.2-2?arch=amd64&os_name=debian&os_version=11"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs20-nodejs-0:20.20.2-2.amd64",
                "product": {
                  "name": "alt-nodejs20-nodejs-0:20.20.2-2.amd64",
                  "product_id": "alt-nodejs20-nodejs-0:20.20.2-2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-nodejs20-nodejs@20.20.2-2?arch=amd64&os_name=debian&os_version=11"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64",
                "product": {
                  "name": "alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64",
                  "product_id": "alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/alt-nodejs20-npm@10.8.2-20.20.2-2?arch=amd64&os_name=debian&os_version=11"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64 as a component of Debian 11",
          "product_id": "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64"
        },
        "product_reference": "alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64 as a component of Debian 11",
          "product_id": "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
        },
        "product_reference": "alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-docs-0:20.20.2-3.amd64 as a component of Debian 11",
          "product_id": "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64"
        },
        "product_reference": "alt-nodejs20-docs-0:20.20.2-3.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-nodejs-0:20.20.2-3.amd64 as a component of Debian 11",
          "product_id": "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64"
        },
        "product_reference": "alt-nodejs20-nodejs-0:20.20.2-3.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64 as a component of Debian 11",
          "product_id": "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64"
        },
        "product_reference": "alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-docs-0:20.20.2-2.amd64 as a component of Debian 11",
          "product_id": "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64"
        },
        "product_reference": "alt-nodejs20-docs-0:20.20.2-2.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-nodejs-0:20.20.2-2.amd64 as a component of Debian 11",
          "product_id": "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64"
        },
        "product_reference": "alt-nodejs20-nodejs-0:20.20.2-2.amd64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64 as a component of Debian 11",
          "product_id": "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
        },
        "product_reference": "alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64",
        "relates_to_product_reference": "Debian-11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-32003",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "notes": [
        {
          "category": "description",
          "text": "`fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. This flaw arises from a missing check in the fs.mkdtemp() API and the impact is a malicious actor could create an arbitrary directory.\n\nThis vulnerability affects all users using the experimental permission model in Node.js 20.\n\nPlease note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
        ],
        "known_affected": [
          "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2023-32003"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2037887",
          "url": "https://hackerone.com/reports/2037887"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JQPELKG2LVTADSB7ME73AV4DXQK47PWK/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JQPELKG2LVTADSB7ME73AV4DXQK47PWK/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PBOZE2QZIBLFFTYWYN23FGKN6HULZ6HX/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PBOZE2QZIBLFFTYWYN23FGKN6HULZ6HX/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20230915-0009/",
          "url": "https://security.netapp.com/advisory/ntap-20230915-0009/"
        }
      ],
      "release_date": "2023-08-15T16:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T11:03:21.892130Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197",
          "product_ids": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197"
        },
        {
          "category": "none_available",
          "date": "2023-08-15T16:15:00Z",
          "details": "Affected",
          "product_ids": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-48933",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB.\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
        ],
        "known_affected": [
          "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-48933"
        }
      ],
      "release_date": "2026-06-26T02:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T11:03:21.892130Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197",
          "product_ids": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197"
        },
        {
          "category": "none_available",
          "date": "2026-06-26T02:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-48930",
      "cwe": {
        "id": "CWE-284",
        "name": "Improper Access Control"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
        ],
        "known_affected": [
          "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-48930"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases"
        }
      ],
      "release_date": "2026-06-26T02:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T11:03:21.892130Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197",
          "product_ids": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197"
        },
        {
          "category": "none_available",
          "date": "2026-06-26T02:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2023-30582",
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an inadequate permission model that fails to restrict file watching through the fs.watchFile API. As a result, malicious actors can monitor files that they do not have explicit read access to.\nPlease note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
        ],
        "known_affected": [
          "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2023-30582"
        }
      ],
      "release_date": "2023-06-20T00:00:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T11:03:21.892130Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197",
          "product_ids": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197"
        },
        {
          "category": "none_available",
          "date": "2023-06-20T00:00:00Z",
          "details": "Affected",
          "product_ids": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-48619",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
        ],
        "known_affected": [
          "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-48619"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases"
        }
      ],
      "release_date": "2026-06-26T02:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T11:03:21.892130Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197",
          "product_ids": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197"
        },
        {
          "category": "none_available",
          "date": "2026-06-26T02:16:00Z",
          "details": "Affected",
          "product_ids": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-37372",
      "notes": [
        {
          "category": "description",
          "text": "Permission model improperly processes UNC paths\n",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
        ],
        "known_affected": [
          "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2024-37372"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T11:03:21.892130Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197",
          "product_ids": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197"
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2023-32005",
      "cwe": {
        "id": "CWE-732",
        "name": "Incorrect Permission Assignment for Critical Resource"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument.\n\nThis flaw arises from an inadequate permission model that fails to restrict file stats through the `fs.statfs` API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to.\n\nThis vulnerability affects all users using the experimental permission model in Node.js 20.\n\nPlease note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
          "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
        ],
        "known_affected": [
          "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
          "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2023-32005"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2051224",
          "url": "https://hackerone.com/reports/2051224"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20231103-0004/",
          "url": "https://security.netapp.com/advisory/ntap-20231103-0004/"
        }
      ],
      "release_date": "2023-09-12T02:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T11:03:21.892130Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197",
          "product_ids": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783422197"
        },
        {
          "category": "none_available",
          "date": "2023-09-12T02:15:00Z",
          "details": "Affected",
          "product_ids": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-2.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-2.amd64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Debian-11:alt-nodejs20-docs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-nodejs-devel-0:20.20.2-3.amd64",
            "Debian-11:alt-nodejs20-npm-0:10.8.2-20.20.2-3.amd64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}