[ALSA-2026:1842] Important: nodejs24 security update
Type:
security
Severity:
important
Release date:
2026-02-06
Description:
Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices. Security Fix(es): * nodejs: Nodejs filesystem permissions bypass (CVE-2025-55132) * nodejs: Nodejs denial of service (CVE-2026-21637) * nodejs: Nodejs denial of service (CVE-2025-59466) * nodejs: Nodejs denial of service (CVE-2025-59465) * nodejs: Nodejs uninitialized memory exposure (CVE-2025-55131) * nodejs: Nodejs file permissions bypass (CVE-2025-55130) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch nodejs24-npm-11.6.2-1.24.13.0.1.el10_1.noarch.rpm 3124f27ac9e1285a726aecbbc047a23ca152293caa72095bbdba52fdf9cad7a9
noarch nodejs24-docs-24.13.0-1.el10_1.noarch.rpm d3c3383e0a8620d0d96532e4cabc540398587c29a21017ddf8a1923501b6e001
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.