[ALSA-2026:55541] Important: nodejs22 security update
Type:
security
Severity:
important
Release date:
2026-08-18
Description:
Node.js is a platform built on Chrome's JavaScript runtime \ for easily building fast, scalable network applications. \ Node.js uses an event-driven, non-blocking I/O model that \ makes it lightweight and efficient, perfect for data-intensive \ real-time applications that run across distributed devices. Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257) * brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152) * ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 nodejs-22.23.1-6.el10_2.aarch64.rpm 04066b532b8828ca7825c8edd3c2db8e4022b3b292a1b01a4bc6e45e891985b8
aarch64 nodejs-devel-22.23.1-6.el10_2.aarch64.rpm 081fb502f810304d9cfd46d300e377bf9efffb74005c04c8a54cd2b4430d3805
aarch64 nodejs-npm-10.9.8-1.22.23.1.6.el10_2.aarch64.rpm 3e5649a5e0dd1b8d56a47412fe55b73e96be6e51ce4cd951987cc04ef950bc17
aarch64 nodejs-libs-22.23.1-6.el10_2.aarch64.rpm 6a582967d11ffd10a365ad594763231e9e826eb19920e15741112d1a496a6bfe
aarch64 nodejs-full-i18n-22.23.1-6.el10_2.aarch64.rpm 72031ffa645716c6768e9c4efe56c7d8b71367aad7f9ea4e0b0957e74652a74c
noarch nodejs-docs-22.23.1-6.el10_2.noarch.rpm a4cf7db461223295f0f82718617815510079e00e6e5e5f79921d8490e5169df3
ppc64le nodejs-full-i18n-22.23.1-6.el10_2.ppc64le.rpm 1fa61f381289f01c4409f656e5d3bbc021820c40a88a422f998751649a889506
ppc64le nodejs-22.23.1-6.el10_2.ppc64le.rpm 215628cd23e7ef863baea7efbd96ff01dbc9519971615a5645dfcefb4a442429
ppc64le nodejs-devel-22.23.1-6.el10_2.ppc64le.rpm a93951f9a657a762ffffd10878228f5fcdaee58e82f574150b41cbe0e818477e
ppc64le nodejs-libs-22.23.1-6.el10_2.ppc64le.rpm e573f928f08bade5c629f8687dfc9c97918ab97c38b235037753fd8006037558
ppc64le nodejs-npm-10.9.8-1.22.23.1.6.el10_2.ppc64le.rpm fe211f4a4b20eb21a6e460516f88e4cc1e88990d7552db0743a419185c2249fc
s390x nodejs-22.23.1-6.el10_2.s390x.rpm 03a41cff0317faf3dfbee7268e2b1fa705c86117d28ac3206a4b08b4b0ad9d42
s390x nodejs-libs-22.23.1-6.el10_2.s390x.rpm 5419c32f43428edcf57e4965edf2cb55b7d6b3d456672211717e28c823555ae0
s390x nodejs-npm-10.9.8-1.22.23.1.6.el10_2.s390x.rpm 6a5329666040fe5e0a45fe23aa458310bee2d9411d3a0bdfd3f0c72b5cb2ab84
s390x nodejs-full-i18n-22.23.1-6.el10_2.s390x.rpm 6d2c08534eb8565c076a4111aca225d5df19c773d1afdc62ee3574684d273ef6
s390x nodejs-devel-22.23.1-6.el10_2.s390x.rpm a30047e9b959197931f6578e19ee2d0174870bd6e8675f3283fb37554e7cdcc1
x86_64 nodejs-22.23.1-6.el10_2.x86_64.rpm 435a77386e232d0253c85b6111808212def9d57b8816f65e2e80e8a78bc04000
x86_64 nodejs-devel-22.23.1-6.el10_2.x86_64.rpm 65b97d6ee340b526c68f7a8a42d7057c1ae5071770f7ec6cb2b26340c21af745
x86_64 nodejs-libs-22.23.1-6.el10_2.x86_64.rpm 7dbd1d82f0b935d584595dfb1baefdcbab3d2cecd947990238172572fe605f51
x86_64 nodejs-npm-10.9.8-1.22.23.1.6.el10_2.x86_64.rpm 9cb191cccdbb7a501903d70b8d5988534c62881c9141db84625417a2fce49326
x86_64 nodejs-full-i18n-22.23.1-6.el10_2.x86_64.rpm e7e167096e2de38747733562d3f2af3b4132e05b57d8724ad03666659d0485d8
x86_64_v2 nodejs-22.23.1-6.el10_2.x86_64_v2.rpm 1d81480579b1d97b87baed29114425b3d4063d304eae795c88c787e9f333e5c1
x86_64_v2 nodejs-devel-22.23.1-6.el10_2.x86_64_v2.rpm 20e7d0b162e1705cef23eb08b0595d5aa499ca3b47446aa5ade00575fa19eaab
x86_64_v2 nodejs-full-i18n-22.23.1-6.el10_2.x86_64_v2.rpm 32a5a1c0b0a211874bfa51d4ba4383cdd3c617c5dd2aa429b22886aee3efcf9d
x86_64_v2 nodejs-npm-10.9.8-1.22.23.1.6.el10_2.x86_64_v2.rpm 8681340e29bdc0982accc334dd523c61391e518ed1450a93c4efbe98f823ed0e
x86_64_v2 nodejs-libs-22.23.1-6.el10_2.x86_64_v2.rpm fb8cf43a2a9123b2cd4a3dabc06cc42e0988ad6422dd8b47711e57b8d99c3c32
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.