Vulnerabilities & Exploits

Debian Issues Security Updates for Node.js and Incus

Debian released advisories updating Node.js and Incus to address multiple vulnerabilities. Node.js flaws can cause denial of service, side-channel attacks, or information disclosure. Incus flaws can cause denial of service or allow execution of arbitrary commands; fixes published for trixie as Node.js 20.19.2+dfsg-1+deb13u2 and Incus 6.0.4-2+deb13u5.

1 source · Mar 29

CVEs in this update

36 CVEs

Across F5OS, BIG-IP, Nessus Network Monitor, and related packages.

16 critical · 20 high · 0 medium · 0 low

0 in CISA KEV · 1 with EPSS above 1%

Highest severity: CVE-2026-4689 · 10.0 CRITICAL

Highest EPSS: CVE-2025-59375 · 1.3%

Showing the top 10 by KEV, EPSS, and severity.

Timeline

Sources

Part of the PlainSec briefing for 2026-03-29

Every edition of this story: Debian Issues Security Updates for Node.js and Incus

More from today