Security News

Cybersecurity news aggregator

🔄
INFO Updates Red Hat Errata

RHSA-2026:35891: Important: nodejs:24 security, bug fix, and enhancement update

  • What: Security update for nodejs:24
  • Impact: Addresses security vulnerabilities in Red Hat Enterprise Linux
Read Full Article →

Red Hat Product Errata RHSA-2026:35891 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:35891 - Security Advisory Overview Updated Packages Synopsis Important: nodejs:24 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the nodejs:24 module is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151) undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678) undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733) undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525) undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697) undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734) nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619) nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930) nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935) nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933) nodejs: Node.js: Certification validation bypass in TLS host verification (CVE-2026-48934) Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency (CVE-2026-48928) nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling (CVE-2026-48615) nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch (CVE-2026-48618) Bug Fix(es) and Enhancement(s): nodejs:24/nodejs: Rebase to the latest Node.js 24 release [rhel-9.8.z] (JIRA:RHEL-186580) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2476810 - CVE-2026-42338 ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input BZ - 2489980 - CVE-2026-12151 undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames BZ - 2490000 - CVE-2026-9678 undici: Undici: Information disclosure due to improper cache-control header parsing BZ - 2490006 - CVE-2026-6733 undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. BZ - 2490008 - CVE-2026-11525 undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header BZ - 2490018 - CVE-2026-9697 undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy BZ - 2490024 - CVE-2026-6734 undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing BZ - 2493325 - CVE-2026-48619 nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames BZ - 2493326 - CVE-2026-48930 nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling BZ - 2493329 - CVE-2026-48935 nodejs: Node.js: Unauthorized file metadata modification BZ - 2493331 - CVE-2026-48933 nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() BZ - 2493332 - CVE-2026-48934 nodejs: Node.js: Certification validation bypass in TLS host verification BZ - 2493333 - CVE-2026-48928 Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency BZ - 2493335 - CVE-2026-48615 nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling BZ - 2493337 - CVE-2026-48618 nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch RHEL-186580 - nodejs:24/nodejs: Rebase to the latest Node.js 24 release [rhel-9.8.z] CVEs CVE-2026-6733 CVE-2026-6734 CVE-2026-9678 CVE-2026-9697 CVE-2026-11525 CVE-2026-12151 CVE-2026-42338 CVE-2026-48615 CVE-2026-48618 CVE-2026-48619 CVE-2026-48928 CVE-2026-48930 CVE-2026-48933 CVE-2026-48934 CVE-2026-48935 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM nodejs-24.18.0-1.module+el9.8.0+24456+b244c3b4.src.rpm SHA-256: 077e0d40771c284206d1a9a860eb73d75c51ad01b0b91c9a6107020ff66180b1 nodejs-nodemon-3.0.3-3.module+el9.8.0+24355+35d95b59.src.rpm SHA-256: 39e03c9063e478b0f9114e9e3a582e779f58d3cb3810c489db8c4902adaf0810 nodejs-packaging-2021.06-6.module+el9.8.0+24355+35d95b59.src.rpm SHA-256: a0f391c74993bc591572766a4c390fbb4a14ae8f621fb124f5378fd3e0c2e208 x86_64 nodejs-docs-24.18.0-1.module+el9.8.0+24456+b244c3b4.noarch.rpm SHA-256: 3665f15b39ac6f87ba3b1b7556db3c5655726087bd7184b4f82295b8db83c309 nodejs-nodemon-3.0.3-3.module+el9.8.0+24355+35d95b59.noarch.rpm SHA-256: 16f347746cfd24419073d2b7930539eb7b4ca7c87a1fdd8f9c59fd9e538eb893 nodejs-packaging-2021.06-6.module+el9.8.0+24355+35d95b59.noarch.rpm SHA-256: 2017dd0b74b58b131a5ab072d257afd7c90eb1f1b30e57372b8bb3d7cf93330b nodejs-packaging-bundler-2021.06-6.module+el9.8.0+24355+35d95b59.noarch.rpm SHA-256: 78df76fdda90d85dce1777d9a14581a2c00f783d56b5a0060430f5b0d588fe2d npm-11.16.0-1.24.18.0.1.module+el9.8.0+24456+b244c3b4.noarch.rpm SHA-256: 8c2bf73548e290cafa9b50fd67ba84b58bb30ffaf266009f3d2a9ff4cd999822 nodejs-docs-24.18.0-1.module+el9.8.0+24456+b244c3b4.noarch.rpm SHA-256: 3665f15b39ac6f87ba3b1b7556db3c5655726087bd7184b4f82295b8db83c309 nodejs-nodemon-3.0.3-3.module+el9.8.0+24355+35d95b59.noarch.rpm SHA-256: 16f347746cfd24419073d2b7930539eb7b4ca7c87a1fdd8f9c59fd9e538eb893 nodejs-packaging-2021.06-6.module+el9.8.0+24355+35d95b59.noarch.rpm SHA-256: 2017dd0b74b58b131a5ab072d257afd7c90eb1f1b30e57372b8bb3d7cf93330b nodejs-packaging-bundler-2021.06-6.module+el9.8.0+24355+35d95b59.noarch.rpm SHA-256: 78df76fdda90d85dce1777d9a14581a2c00f783d56b5a0060430f5b0d588fe2d npm-11.16.0-1.24.18.0.1.module+el9.8.0+24456+b244c3b4.noarch.rpm SHA-256: 8c2bf73548e290cafa9b50fd67ba84b58bb30ffaf266009f3d2a9ff4cd999822 nodejs-24.18.0-1.module+el9.8.0+24456+b244c3b4.x86_64.rpm SHA-256: 34df6db8a3bc602bcc53d0b237414306f66fc0b31c33b0cf3e06aba264785cf7 nodejs-debuginfo-24.18.0-1.module+el9.8.0+24456+b244c3b4.x86_64.rpm SHA-256: bedc9f4a57410461a0df219f8dc1d7b650a379a3028a16c4b54758fa33f2fceb nodejs-debugsource-24.18.0-1.module+el9.8.0+24456+b244c3b4.x86_64.rpm SHA-256: f584d5e538e20f04433d3530ce19a5bef11bc2c7004f858124f4495e1dc22835 nodejs-devel-24.18.0-1.module+el9.8.0+24456+b244c3b4.x86_64.rpm SHA-256: 547c6c6f32558d7759683755364185ba04d9c57c435c6628519c9653c07ce769 nodejs-docs-24.18.0-1.module+el9.8.0+24456+b244c3b4.noarch.rpm SHA-256: 3665f15b39ac6f87ba3b1b7556db3c5655726087bd7184b4f82295b8db83c309 nodejs-full-i18n-24.18.0-1.module+el9.8.0+24456+b244c3b4.x86_64.rpm SHA-256: bf44bf2789ae60a91cd801caeca800e69ed15759f28a1fe75752477c39e69b4e nodejs-libs-24.18.0-1.module+el9.8.0+24456+b244c3b4.x86_64.rpm SHA-256: 0fe4ec1f1dc0c19f7ffa9caaba12425646da6dc245ddc1e188bc736c118f9ba9 nodejs-libs-debuginfo-24.18.0-1.module+el9.8.0+24456+b244c3b4.x86_64.rpm SHA-256: 43c8c87e4903dc85a4da1c125ec293c680811b3227ed49fe12bc807f62c173de nodejs-nodemon-3.0.3-3.module+el9.8.0+24355+35d95b59.noarch.rpm SHA-256: 16f347746cfd24419073d2b7930539eb7b4ca7c87a1fdd8f9c59fd9e538eb893 nodejs-packaging-2021.06-6.module+el9.8.0+24355+35d95b59.noarch.rpm SHA-256: 2017dd0b74b58b131a5ab072d257afd7c90eb1f1b30e57372b8bb3d7cf93330b nodejs-packaging-bundler-2021.06-6.module+el9.8.0+24355+35d95b59.noarch.rpm SHA-256: 78df76fdda90d85dce1777d9a14581a2c00f783d56b5a0060430f5b0d588fe2d npm-11.16.0-1.24.18.0.1.module+el9.8.0+24456+b244c3b4.noarch.rpm SHA-256: 8c2bf73548e290cafa9b50fd67ba84b58bb30ffaf266009f3d2a9ff4cd999822 v8-13.6-devel-13.6.233.17-1.24.18.0.1.module+el9.8.0+24456+b244c3b4.x86_64.rpm SHA-256:

Share this article