Red Hat Product Errata RHSA-2026:39246 - Security Advisory Issued: 2026-07-14 Updated: 2026-07-14 RHSA-2026:39246 - Security Advisory Overview Updated Packages Synopsis Important: nodejs22 security update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for nodejs22 is now available for Red Hat Enterprise Linux 10.0 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Node.js is a platform built on Chrome's JavaScript runtime \ for easily building fast, scalable network applications. \ Node.js uses an event-driven, non-blocking I/O model that \ makes it lightweight and efficient, perfect for data-intensive \ real-time applications that run across distributed devices. Security Fix(es): ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151) nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933) nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling (CVE-2026-48615) nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch (CVE-2026-48618) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 x86_64 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 s390x Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 ppc64le Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.0 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.0 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.0 x86_64 Fixes BZ - 2476810 - CVE-2026-42338 ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input BZ - 2489980 - CVE-2026-12151 undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames BZ - 2493331 - CVE-2026-48933 nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() BZ - 2493335 - CVE-2026-48615 nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling BZ - 2493337 - CVE-2026-48618 nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch CVEs CVE-2026-12151 CVE-2026-42338 CVE-2026-48615 CVE-2026-48618 CVE-2026-48933 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.0 SRPM nodejs22-22.23.1-2.el10_0.src.rpm SHA-256: 1735cf43c415fd43dfd5b0c23a8fe9c917f4f24e92221fde6e008c4e6a804bfa x86_64 nodejs-22.23.1-2.el10_0.x86_64.rpm SHA-256: 4ee863ca23d7bb05331b59f14618147ea37a1de2aefd3fb9571dca0d4eaba3a4 nodejs-debuginfo-22.23.1-2.el10_0.x86_64.rpm SHA-256: 28b638c640daba95fe7e80884946012de1ff2f1f74d48abd8a1b7b4f5e8e56b5 nodejs-devel-22.23.1-2.el10_0.x86_64.rpm SHA-256: cded868070a5e31228e611af9aaf039bc9c1122f4434a31a8c9034c60fe95342 nodejs-docs-22.23.1-2.el10_0.noarch.rpm SHA-256: 939c397ec03359fefb059a5b60b80e553c4d7892e928fc8612466b28b15754c0 nodejs-full-i18n-22.23.1-2.el10_0.x86_64.rpm SHA-256: 53da246efba239e55367233964177afca109e13f4eea4616e8d9c640abb1739d nodejs-libs-22.23.1-2.el10_0.x86_64.rpm SHA-256: 592377424d2deb6cd6696a9caf6972d25eaf525ea6b2d7146dc473354813640a nodejs-libs-debuginfo-22.23.1-2.el10_0.x86_64.rpm SHA-256: 3695561b2aa8c51fcc89f1c3a32c392f5f6695b0c0c528bac692c59ffef4e047 nodejs-npm-10.9.8-1.22.23.1.2.el10_0.x86_64.rpm SHA-256: ba10d557c5d5b93a07ddc932ed4e6492f6d278c7ed0d0a03a552dc6ccb8238f9 nodejs22-debuginfo-22.23.1-2.el10_0.x86_64.rpm SHA-256: 2cda2a2abca5f3ec29669a2ec1b727a9d5b9e7ce4b89a6938830dcca9d9e58c8 nodejs22-debugsource-22.23.1-2.el10_0.x86_64.rpm SHA-256: a9aba56ade831978ffbeaf61382d62eb44b1a8e4e19455721ea519f31fd62d85 Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.0 SRPM nodejs22-22.23.1-2.el10_0.src.rpm SHA-256: 1735cf43c415fd43dfd5b0c23a8fe9c917f4f24e92221fde6e008c4e6a804bfa s390x nodejs-22.23.1-2.el10_0.s390x.rpm SHA-256: 06b440bb451073831af118d21a71ca18bcedf720fa939740184a5b235eaedc6a nodejs-debuginfo-22.23.1-2.el10_0.s390x.rpm SHA-256: 32d9387d11cdc9f667e38cc57460a246aca9f6fcc7e8f6ad87e10965e9d7c7e6 nodejs-devel-22.23.1-2.el10_0.s390x.rpm SHA-256: 6c99bc71ceaeab136ea77ea1bc9837496f41306c4adfe3fd09c1776837786f51 nodejs-docs-22.23.1-2.el10_0.noarch.rpm SHA-256: 939c397ec03359fefb059a5b60b80e553c4d7892e928fc8612466b28b15754c0 nodejs-full-i18n-22.23.1-2.el10_0.s390x.rpm SHA-256: 800e27bd513f7a46de69295d911d21e8db18b1b28e35d50cce862160ecbdbdf7 nodejs-libs-22.23.1-2.el10_0.s390x.rpm SHA-256: e2c36c7f57243f178dd20fa69509de21cfebe42145de6e89841bc391424c0ae8 nodejs-libs-debuginfo-22.23.1-2.el10_0.s390x.rpm SHA-256: 04b0547dc1a76f8459c4aef7d648745fcd546b20618882341788a82f4cb8db40 nodejs-npm-10.9.8-1.22.23.1.2.el10_0.s390x.rpm SHA-256: 35211829cbe614923e4cb4a843575ec017943f8052297c46411427a134b7bec5 nodejs22-debuginfo-22.23.1-2.el10_0.s390x.rpm SHA-256: 5fb57d1182564d53a484acef18faced6681b028d5d689f718e64b5286e084066 nodejs22-debugsource-22.23.1-2.el10_0.s390x.rpm SHA-256: 0b9c4208df01cafb5eb089ea669e4070fbf69979a03f8a4f4fd6a43f32c9d2f3 Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.0 SRPM nodejs22-22.23.1-2.el10_0.src.rpm SHA-256: 1735cf43c415fd43dfd5b0c23a8fe9c917f4f24e92221fde6e008c4e6a804bfa ppc64le nodejs-22.23.1-2.el10_0.ppc64le.rpm SHA-256: 3233e0ffe7044f862a7fe06f59acbd5a99dfb088cafa26a86401374e8349437c nodejs-debuginfo-22.23.1-2.el10_0.ppc64le.rpm SHA-256: d7578b0a4a12f94458b89995f72c37e38d4760f3cff0949369eb3c230dc13825 nodejs-devel-22.23.1-2.el10_0.ppc64le.rpm SHA-256: 5c55b87009f24b66f0461d903ad1015fee3d7008d03d9ae03eb4f41b43a483f1 nodejs-docs-22.23.1-2.el10_0.noarch.rpm SHA-256: 939c397ec03359fefb059a5b60b80e553c4d7892e928fc8612466b28b15754c0 nodejs-full-i18n-22.23.1-2.el10_0.ppc64le.rpm SHA-256: 605cdf4f9666a3c2334b42ee226172b1fce7b4b58a5a3cce4ef46f684ef19dc1 nodejs-libs-22.23.1-2.el10_0.ppc64le.rpm SHA-256: bc08c702e98a8e5cb4370e07491ed9556acd91dfc7e729cf167b6ba604ef0217 nodejs-libs-debuginfo-22.23.1-2.el10_0.ppc64le.rpm SHA-256: 089c2ad57b01600c1e7ee3b23d337b521e5d5eaf4ea0cb7ac51e7abb94fa7adb nodejs-npm-10.9.8-1.22.23.1.2.el10_0.ppc64le.rpm SHA-256: 9ca85813c8b5e9ac44f94a1b46ac27e5f98276b0d5df979fb274e8b8560c8f12 nodejs22-debuginfo-22.23.1-2.el10_0.ppc64le.rpm SHA-256: 0e84327442f37ce8d6aa998545432624d819bfae158e42c95fe78864c0c1c124 nodejs22-debugsource-22.23.1-2.el10_0.ppc64le.rpm SHA-256: bd0f8c9580535408818cd735ddec0c2417138f69bbde74e81838e42fb1d2b408 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.0 SRPM nodejs22-22.23.1-2.el10_0.src.rpm SHA-256: 1735cf43c415fd43dfd5b0c23a8fe9c917f4f24e92221fde6e008c4e6a804bfa aarch64 nodejs-22.23.1-2.el10_0.aarch64.rpm SHA-256: 25b30b1650681b5310edb2307538a2d78dfae28b912406485967f3daf49ac3b9 nodejs-debuginfo-22.23.1-2.el10_0.aarch64.rpm SHA-256: 95f63806c1ada95352ac293d48cc82a9e66495e9a455fa73f1260b268b0aebe1 nodejs-devel-22.23.1-2.el10_0.aarch64.rpm SHA-256: 5d97626bdedf65be428e1965d35182a6dd74dadf60f5dd581d08dc28b88539ff nodejs-docs-22.23.1-2.el10_0.noarch.rpm SHA-256: 939c397ec03359fefb059a5b60b80e553c4d7892e928fc8612466b28b15754c0 nodejs-full-i18n-22.23.1-2.el10_0.aarch64.rpm SHA-256: 2ce3e1b15cf8ea8d3ebfbd7d22626dcc4292fe051f561306ec5d4ee004ee51c8 nodejs-libs-22.23.1-2.el10_0.aarch64.rpm SHA-256: abe786d5c8a7a8cde7df045f13bdeb674dce5ec194485ea7e590b6b30a7233ce nodejs-libs-debuginfo-22.23.1-2.el10_0.aarch64.rpm SHA-256: 1e173600728772be0dd1950cf9c7e0ce1501f5c32629dde1c1743806a614a470 nodejs-npm-10.9.8-1.22.23.1.2.el10_0.aarch64.rpm SHA-256: 0f1b959dd4516fa60019f2a8d181f3964f6af9e4221f49f3051bf7fd2f823327 nodejs22-debuginfo-22.23.1-2.el10_0.aarch64.rpm SHA-256: 9dceb5d88c6dd51c85fa8efc2350104610d192ca548c88bc412a1ca27cc62308 nodejs22-debugsource-22.23.1-2.el10_0.aarch64.rpm SHA-256: 211f5de28b8ff82127e27c7529ccc86526e29e215b209a24bacd9f2a33e60a10 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.0 SRPM nodejs22-22.23.1-2.el10_0.src.rpm SHA-256: 1735cf43c415fd43dfd5b0c23a8fe9c917f4f24e92221fde6e008c4e6a804bfa aarch64 nodejs-22.23.1-2.el10_0.aarch64.rpm SHA-256: 25b30b1650681b5310edb2307538a2d78dfae28b912406485967f3daf49ac3b9 nodejs-debuginfo-22.23.1-2.el10_0.aarch64.rpm SHA-256: 95f63806c1ada95352ac293d48cc82a9e66495e9a455fa73f1260b268b0aebe1 nodejs-devel-22.23.1-2.el10_0.aarch64.rpm SHA-256: 5d97626bdedf65be428e1965d35182a6dd74dadf60f5dd581d08dc28b88539ff nodejs-docs-22.23.1-2.el10_0.noarch.rpm SHA-256: 939c397ec03359fefb059a5b60b80e553c4d7892e928fc8612466b28b15754c0 nodejs-full-i18n-22.23.1-2.el10_0.aarch64.rpm SHA-256: 2ce3e1b15cf8ea8d3ebfbd7d22626dcc4292fe051f561306ec5d4ee004ee51c8 nodejs-libs-22.23.1-2.el10_0.aarch64.rpm SHA-256: abe786d5c8a7a8cde7df045f13bdeb674dce5ec194485ea7e590b6b30a7233ce nodejs-libs-debuginfo-22.23.1-2.el10_0.aarch64.rpm SHA-256: 1e173600728772be0dd1950cf9c7e0ce1501f5c32629dde1c1743806a614a470 nodejs-npm-10.9.8-1.22.23.1.2.el10_0
This Red Hat advisory addresses five vulnerabilities in Node.js 22, including a high-severity Denial of Service in the `undici` HTTP client (CVE-2026-12151, CVSS 7.5) due to unbounded memory growth from WebSocket frames, and a high-severity DoS in WebCrypto's `subtle.encrypt()` (CVE-2026-48933, CVSS 7.5) via large inputs. The `undici` vulnerability affects versions 6.17.0 to 6.26.x, 7.0.0 to 7.27.x, and 8.0.0 to 8.4.x, requiring an upgrade to versions 6.27.0, 7.28.0, or 8.5.0 respectively. The advisory provides patched packages for Red Hat Enterprise Linux 10.0 Extended Update Support.