Red Hat Product Errata RHSA-2026:35842 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:35842 - Security Advisory Overview Updated Packages Synopsis Important: nodejs22 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for nodejs22 is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Node.js is a platform built on Chrome's JavaScript runtime \ for easily building fast, scalable network applications. \ Node.js uses an event-driven, non-blocking I/O model that \ makes it lightweight and efficient, perfect for data-intensive \ real-time applications that run across distributed devices. Security Fix(es): ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151) undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678) undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733) undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525) nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619) nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930) nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935) nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933) nodejs: Node.js: Certification validation bypass in TLS host verification (CVE-2026-48934) Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency (CVE-2026-48928) nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling (CVE-2026-48615) nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch (CVE-2026-48618) Bug Fix(es) and Enhancement(s): nodejs22: Rebase to the latest Node.js 22 release [rhel-10.2.z] (JIRA:RHEL-186623) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2476810 - CVE-2026-42338 ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input BZ - 2489980 - CVE-2026-12151 undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames BZ - 2490000 - CVE-2026-9678 undici: Undici: Information disclosure due to improper cache-control header parsing BZ - 2490006 - CVE-2026-6733 undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. BZ - 2490008 - CVE-2026-11525 undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header BZ - 2493325 - CVE-2026-48619 nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames BZ - 2493326 - CVE-2026-48930 nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling BZ - 2493329 - CVE-2026-48935 nodejs: Node.js: Unauthorized file metadata modification BZ - 2493331 - CVE-2026-48933 nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() BZ - 2493332 - CVE-2026-48934 nodejs: Node.js: Certification validation bypass in TLS host verification BZ - 2493333 - CVE-2026-48928 Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency BZ - 2493335 - CVE-2026-48615 nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling BZ - 2493337 - CVE-2026-48618 nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch RHEL-186623 - nodejs22: Rebase to the latest Node.js 22 release [rhel-10.2.z] CVEs CVE-2026-6733 CVE-2026-9678 CVE-2026-11525 CVE-2026-12151 CVE-2026-42338 CVE-2026-48615 CVE-2026-48618 CVE-2026-48619 CVE-2026-48928 CVE-2026-48930 CVE-2026-48933 CVE-2026-48934 CVE-2026-48935 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM nodejs22-22.23.1-2.el10_2.src.rpm SHA-256: 79e9aa452184bd21827ad5f46d02ab7186a37181f3442732b73ea4bcde787e31 x86_64 nodejs-22.23.1-2.el10_2.x86_64.rpm SHA-256: f33e48c9101142190fe42423dbb465b0ad11cfa19c6d57c7264604a970178835 nodejs-debuginfo-22.23.1-2.el10_2.x86_64.rpm SHA-256: 43f2f70ffbdc025c894a6a20c1f1ba68548bb1ff44ccbfbc9cc22e1289371a59 nodejs-devel-22.23.1-2.el10_2.x86_64.rpm SHA-256: 781e85edf4e823baf2be19d09d568ee4638eabfb7e35fefbe246360e124a6ec5 nodejs-docs-22.23.1-2.el10_2.noarch.rpm SHA-256: 8810c54e11a2f2cd44fd7f11c2db966c856bd792c5a1219345fedd0f91180883 nodejs-full-i18n-22.23.1-2.el10_2.x86_64.rpm SHA-256: 9654222e42c1bbe35a69e0a9c3b0c4952f00ae862be8ab889deb090437123f38 nodejs-libs-22.23.1-2.el10_2.x86_64.rpm SHA-256: d9c98ec69c19d5a6cbdfe4636ce7d9330d5b9761576ffb4e8734ab94e67c4b56 nodejs-libs-debuginfo-22.23.1-2.el10_2.x86_64.rpm SHA-256: ea74f1f0982b1a4c3b7e53ed8e3597a730e4cd9a679f02ee8d2aa5d00f1de6d6 nodejs-npm-10.9.8-1.22.23.1.2.el10_2.x86_64.rpm SHA-256: b678dcac31d756fb973e94c02c8925270153f9f850167d85fa297c7206a50ca0 nodejs22-debuginfo-22.23.1-2.el10_2.x86_64.rpm SHA-256: 0cf69e618f29c87554d5ab9b6bd167ba07ddd6cd3d7c904b1ca52dc2c6eb99d7 nodejs22-debugsource-22.23.1-2.el10_2.x86_64.rpm SHA-256: d4d18356a570afb83c938554507dbd5cc73ec07b9d09690514b3855542ca14dd Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM nodejs22-22.23.1-2.el10_2.src.rpm SHA-256: 79e9aa452184bd21827ad5f46d02ab7186a37181f3442732b73ea4bcde787e31 x86_64 nodejs-22.23.1-2.el10_2.x86_64.rpm SHA-256: f33e48c9101142190fe42423dbb465b0ad11cfa19c6d57c7264604a970178835 nodejs-debuginfo-22.23.1-2.el10_2.x86_64.rpm SHA-256: 43f2f70ffbdc025c894a6a20c1f1ba68548bb1ff44ccbfbc9cc22e1289371a59 nodejs-devel-22.23.1-2.el10_2.x86_64.rpm SHA-256: 781e85edf4e823baf2be19d09d568ee4638eabfb7e35fefbe246360e124a6ec5 nodejs-docs-22.23.1-2.el10_2.noarch.rpm SHA-256: 8810c54e11a2f2cd44fd7f11c2db966c856bd792c5a1219345fedd0f91180883 nodejs-full-i18n-22.23.1-2.el10_2.x86_64.rpm SHA-256: 9654222e42c1bbe35a69e0a9c3b0c4952f00ae862be8ab889deb090437123f38 nodejs-libs-22.23.1-2.el10_2.x86_64.rpm SHA-256: d9c98ec69c19d5a6cbdfe4636ce7d9330d5b9761576ffb4e8734ab94e67c4b56 nodejs-libs-debuginfo-22.23.1-2.el10_2.x86_64.rpm SHA-256: ea74f1f0982b1a4c3b7e53ed8e3597a730e4cd9a679f02ee8d2aa5d00f1de6d6 nodejs-npm-10.9.8-1.22.23.1.2.el10_2.x86_64.rpm SHA-256: b678dcac31d756fb973e94c02c8925270153f9f850167d85fa297c7206a50ca0 nodejs22-debuginfo-22.23.1-2.el10_2.x86_64.rpm SHA-256: 0cf69e618f29c87554d5ab9b6bd167ba07ddd6cd3d7c904b1ca52dc2c6eb99d7 nodejs22-debugsource-22.23.1-2.el10_2.x86_64.rpm SHA-256: d4d18356a570afb83c938554507dbd5cc73ec07b9d09690514b3855542ca14dd Red Hat Enterprise Linux for IBM z Systems 10 SRPM nodejs22-22.23.1-2.el10_2.src.rpm SHA-256: 79e9aa452184bd21827ad5f46d02ab7186a37181f3442732b73ea4bcde787e31 s390x nodejs-22.23.1-2.el10_2.s390x.rpm SHA-256: 97e44e5a47a8de849da13ec2ed8eabecd4e5bb66a6fb48d2675f12b756a7aa61 nodejs-debuginfo-22.23.1-2.el10_2.s390x.rpm SHA-256: c2ff9b87e75d2133f77ebd2f3a15accbc26e84c851cf8b25e78ea6eb1ed379a5 nodejs-devel-22.23.1-2.el10_2.s390x.rpm SHA-256: 1eee6f04abd3decf2f236a0ed395260ffb1e72f15f346c6c8f75b91d7289e345 nodejs-docs-22.23.1-2.el10_2.noarch.rpm SHA-256: 8810c54e11a2f2cd44fd7f11c2db966c856bd792c5a1219345fedd0f91180883 nodejs-full-i18n-22.23.1-2.el10_2.s390x.rpm SHA-256: 25b2ac1bcfb089234a5ab435445f24517e9a8c9d51b2ef36da8e68d17246da62 nodejs-libs-22.23.1-2.el10_2.s390x.rpm SHA-256: 7439953f193fbbeb6bc2a6be20891855bf71fd1081ad4a075f52fddf894aa96b nodejs-libs-debuginfo-22.23.1-2.el10_2.s390x.rpm SHA-256: b365b955ac7e9ab45d5df998425cf51e2baf45651ab568b321d3dd8340272628 nodejs-npm-10.9.8-1.22.23.1.2.el10_2.s390x.rpm SHA-256: 8720c5ba39b78c735e3beeeba17be40eaa4ca7c737c8004205c1291ca00e7a90 nodejs22-debuginfo-22.23.1-2.el10_2.s390x.rpm SHA-256: f2717193dd185a4cdf3cf2b321df74505845d59f06fe21438316029af7113df8 nodejs22-debugsource-22.23.1-2.el10_2.s390x.rpm SHA-256: 7c3d7bc52aa51be4e2e9bf931e80c58a2e48839a59d1a4fe
This advisory addresses multiple security vulnerabilities in Node.js 22 for RHEL 10, including a high-severity denial of service in the `undici` HTTP client (CVE-2026-12151, CVSS 7.5) due to unbounded memory growth from WebSocket frames, affecting `undici` versions 6.17.0 through 6.26.0, 7.0.0 through 7.27.0, and 8.0.0 through 8.4.0, which are fixed in versions 6.27.0, 7.28.0, and 8.5.0 respectively. Other notable issues include a TLS hostname verification bypass (CVE-2026-48934), a WebCrypto DoS via large input to `subtle.encrypt()` (CVE-2026-48933), and an XSS vulnerability in the `ip-address` library (CVE-2026-42338, CVSS 6.1). The update also includes bug fixes and enhancements, and affected systems should apply the provided Red Hat package update.