[ALSA-2026:48033] Important: nodejs22 security update
Type:
security
Severity:
important
Release date:
2026-07-30
Description:
Node.js is a platform built on Chrome's JavaScript runtime \ for easily building fast, scalable network applications. \ Node.js uses an event-driven, non-blocking I/O model that \ makes it lightweight and efficient, perfect for data-intensive \ real-time applications that run across distributed devices. Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) * tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874) * tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 nodejs-libs-22.23.1-4.el10_2.aarch64.rpm 5422d032a9ed4d7a40abcc9413fde4e50bfd51f47496ca4cebe86a3bcb13a325
aarch64 nodejs-npm-10.9.8-1.22.23.1.4.el10_2.aarch64.rpm 6f38c50904cdca0aecc7cfc638072b3f8c84f521412a5909425fd71e54276a57
aarch64 nodejs-devel-22.23.1-4.el10_2.aarch64.rpm 8589bde7d4d292597f3c791a510dd41b8fda9a0885479aade0663742d31fea11
aarch64 nodejs-22.23.1-4.el10_2.aarch64.rpm a0dffdbcfb90e9f2c8cd9ee9ccfbfd0d5ac2de2cfd2ac0555c80c2cf5c75199e
aarch64 nodejs-full-i18n-22.23.1-4.el10_2.aarch64.rpm d5eb299f5fe36dee50ea58e2b99af548cdc63c90702c43e546f2528efd7aa4ae
noarch nodejs-docs-22.23.1-4.el10_2.noarch.rpm 4a83c12224f35412b6625e9741ade14adf2898f3deb3cc76c129e06984205bf2
ppc64le nodejs-22.23.1-4.el10_2.ppc64le.rpm 657305d71927e4f56129ad52ae7f0de70854f9d9695b8fc4ce1a51155f33a26c
ppc64le nodejs-libs-22.23.1-4.el10_2.ppc64le.rpm 71ac9b072f92115478875a37f6df7b456ccea61a84ea8ed16ace597303463a67
ppc64le nodejs-devel-22.23.1-4.el10_2.ppc64le.rpm 93f95481d4db7cfae629ef1ed7773a40a1a783615d098cbbdf34b486afba7cf0
ppc64le nodejs-full-i18n-22.23.1-4.el10_2.ppc64le.rpm aae046b579c73185fe61f2443fa7cbd2a3d34be3bf202bd6f3d6f113d2a19709
ppc64le nodejs-npm-10.9.8-1.22.23.1.4.el10_2.ppc64le.rpm f1d380e9a4320e450a6e251a2f789b06c525c50b2d024809a072268b75f218c0
s390x nodejs-22.23.1-4.el10_2.s390x.rpm 1e0355965f5a90998ad7565363a40d0e315e84930fd6cb9f6942e43a38f86fd2
s390x nodejs-npm-10.9.8-1.22.23.1.4.el10_2.s390x.rpm 7a66fa83c8259e46dfe28706a1ab95db59730f0597f4c831c7d93d69cfd78ce5
s390x nodejs-devel-22.23.1-4.el10_2.s390x.rpm 7c8e28efc5e7970978a05e0464498b312dd778378042c976d86dc78ba148d660
s390x nodejs-full-i18n-22.23.1-4.el10_2.s390x.rpm b5be071eb10586b120d78d6bc4beb0b693c49549e18b4df54ddad2e2c0e66522
s390x nodejs-libs-22.23.1-4.el10_2.s390x.rpm b7c786287bad4c41be7824f91239f41c9a8827db41167ef9f8dea62f39adb425
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.