[ALSA-2026:58819] Important: nodejs24 security update
Type:
security
Severity:
important
Release date:
2026-08-25
Description:
Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices. Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257) * ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification (CVE-2026-54272) * brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152) * ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 nodejs24-devel-24.18.0-5.el10_2.aarch64.rpm 3b7039ec9cc453d2b69835b04be13b3b504143c954aaf295dd5648fb85a72354
aarch64 nodejs24-24.18.0-5.el10_2.aarch64.rpm 45a941bee15b368528bebb27a4fc4bf429f47c5a22bd23983cd3c57d4dbe617b
aarch64 nodejs24-libs-24.18.0-5.el10_2.aarch64.rpm 9c26d6d75a7c517c93705da59dc2e4e714d1c239597cc675157a3a128fbdb17a
aarch64 nodejs24-full-i18n-24.18.0-5.el10_2.aarch64.rpm c4fae0e893afce044f42ba648b0561cdae2b1064819246d3dd057b56820f3249
noarch nodejs24-npm-11.16.0-1.24.18.0.5.el10_2.noarch.rpm 0b5823d155438be9e50559a2b2516af1f168e0c86471037562a2f1a8b8cc92f1
noarch nodejs24-docs-24.18.0-5.el10_2.noarch.rpm f376c79686cb878dbaf4e4b6b47534b7dad0ad97bbd2d659ad2f239bdb1d023c
ppc64le nodejs24-libs-24.18.0-5.el10_2.ppc64le.rpm 2e79872920156866c8a171721da16cb990aac23a3d1929a4cf79130392b40a6a
ppc64le nodejs24-24.18.0-5.el10_2.ppc64le.rpm 77ecb92756c7383c3ed7fc8bbb5c04477bfbd489d895933c2db7ec88711afaa8
ppc64le nodejs24-full-i18n-24.18.0-5.el10_2.ppc64le.rpm d767ef97a2966157684948810187ae7303098e4703d8ba7ba7d295eb2b1e8b93
ppc64le nodejs24-devel-24.18.0-5.el10_2.ppc64le.rpm f1c2d8c82a201735ac0cae4f6146f3493ebe21af5d3c10617969eb815607858e
s390x nodejs24-24.18.0-5.el10_2.s390x.rpm 554fabac3e6e13d6f908a9f56c8faabbabf37973b49951fb96286f70b6723c2d
s390x nodejs24-devel-24.18.0-5.el10_2.s390x.rpm d51914a8db148cd7d4bd817594b4c08cac7164fa8e0b4e8a667233203ce79079
s390x nodejs24-libs-24.18.0-5.el10_2.s390x.rpm e1b18d3cb372b35a4e0d9cb498fedb2f6f7b65cb5f9bd5cbd8439cc87116c6e8
s390x nodejs24-full-i18n-24.18.0-5.el10_2.s390x.rpm e3976d92db25a965d5ccbc0c692b7aacce542f3b146f174f4b1d8df506cfbd30
x86_64 nodejs24-devel-24.18.0-5.el10_2.x86_64.rpm 34f7cad2a2ffec5b68bc403b3d7c28f643a518f1cf8a4a6cd2d46f5ad6918268
x86_64 nodejs24-24.18.0-5.el10_2.x86_64.rpm 49da1ea61d5aed1a3c78a67b0ee8cef771cc9c3325403f976137ddee5908b533
x86_64 nodejs24-full-i18n-24.18.0-5.el10_2.x86_64.rpm 6d239c21d03b2447ea8672e1e28729df24938248e48ea97bc5ec0b8ff737428c
x86_64 nodejs24-libs-24.18.0-5.el10_2.x86_64.rpm cb9972ea7fda5f1e770ac7f6faf20ebf392c9b334cb3c0e5ca05f94d6602b428
x86_64_v2 nodejs24-devel-24.18.0-5.el10_2.x86_64_v2.rpm 4a901e8accd46aef9b841a4bbd63188984520f0581b7204fccfaf71f68f159e0
x86_64_v2 nodejs24-24.18.0-5.el10_2.x86_64_v2.rpm a2d01a9d99241b062a970c22e7bbe7c78f74ff27842c0a14a8f39cc7ee2595bc
x86_64_v2 nodejs24-full-i18n-24.18.0-5.el10_2.x86_64_v2.rpm a9e74fe3135119185c116ee214435b9722c03e6e326e0d5d701263efc7fd108b
x86_64_v2 nodejs24-libs-24.18.0-5.el10_2.x86_64_v2.rpm dd3eb4f08167b19ed8b008229fe2c72287439031713dfaf2fa4eb004b7f3b376
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.