[ALSA-2026:73428] Important: nodejs24 security, bug fix, and enhancement update
Type:
security
Severity:
important
Release date:
2026-09-30
Description:
Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices. Security Fix(es): * undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation (CVE-2026-85152) * undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options (CVE-2026-84961) * undici: undici: Denial of Service via unrequested WebSocket subprotocol (CVE-2026-19534) Bug Fix(es) and Enhancement(s): * nodejs24: Rebase to the latest Node.js 24 release [almalinux-10] (JIRA:AlmaLinux-249187) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 nodejs24-full-i18n-24.21.0-1.el10_2.aarch64.rpm 7801c6e666ab708e902c62d610264eb43400a1374858445afaa601042b8f312c
aarch64 nodejs24-24.21.0-1.el10_2.aarch64.rpm 90585f81ad3a3373df1b3401743d4ffee865518485a67d1e0029964bcba85dc1
aarch64 nodejs24-libs-24.21.0-1.el10_2.aarch64.rpm d1a7f724f7992879cf9eaa9822a107fc4945d30d8b9054cde5a538f177d4e1d7
aarch64 nodejs24-devel-24.21.0-1.el10_2.aarch64.rpm f4a3cba3fb88d87950bed205f721bf15046808c38062b8e51db14aec52d0e010
noarch nodejs24-docs-24.21.0-1.el10_2.noarch.rpm 3c0582da0fa349b5c85a8671a5ccff46d1d89830e1e263672e2e93e4eb5161c5
noarch nodejs24-npm-11.19.0-1.24.21.0.1.el10_2.noarch.rpm c33582aee585c85053bce7f5822e3f7bccd46c315de9ed48e5522daeeeec7080
ppc64le nodejs24-24.21.0-1.el10_2.ppc64le.rpm 130900c6e5d1716ea177dc3118eae2ea8077c69bb8f548f1a13da62d1a73595f
ppc64le nodejs24-libs-24.21.0-1.el10_2.ppc64le.rpm 46327a3b3c4efa1784a547e9ecf3d4a95feb35c8f148fbba3066faf6202b5d65
ppc64le nodejs24-full-i18n-24.21.0-1.el10_2.ppc64le.rpm 50abe5f25732a5567048fb4f218c228e1c044004b4e9a7080187d33223615d59
ppc64le nodejs24-devel-24.21.0-1.el10_2.ppc64le.rpm ad676237903b9b640613a988312f9bf8d8557119e32593c4d0c76563e9513c8f
s390x nodejs24-24.21.0-1.el10_2.s390x.rpm 76bb2e46b4520fd16195e0f62a38a4ed6633fc832dac7b0c8b91e33a27b00179
s390x nodejs24-libs-24.21.0-1.el10_2.s390x.rpm d3dde3cba6582ab3c227d69ee119c10d3a92cb3123ee13b7c95f10703dc67925
s390x nodejs24-full-i18n-24.21.0-1.el10_2.s390x.rpm d6b93fe50cf7a82e17b8506cfeaf666e499bfc7980106addca5d87c688d25678
s390x nodejs24-devel-24.21.0-1.el10_2.s390x.rpm e54f67d563bcd6043723d1f2180496383fd31e370c7cbd7e5bda526ed49dcd81
x86_64 nodejs24-devel-24.21.0-1.el10_2.x86_64.rpm 24dc4b4bf6ce8903f0f7dd9c75543771c88eec54a5a39c323032692392cc9687
x86_64 nodejs24-libs-24.21.0-1.el10_2.x86_64.rpm 2d5b5442ce8c087b8dc1b45d7b3fc4a60c9c1d9f4d686ce0a997855d38cbf469
x86_64 nodejs24-full-i18n-24.21.0-1.el10_2.x86_64.rpm 744334b4c60b7ceab18129dc88974c37a0461cdd2ad25ad21c0ccaba114c3273
x86_64 nodejs24-24.21.0-1.el10_2.x86_64.rpm e904397d02bff79dacd50c5dca92f3e42f098f543c98e2d1ca8e77d2cf591b84
x86_64_v2 nodejs24-devel-24.21.0-1.el10_2.x86_64_v2.rpm 0cad9b5eeb80cb86e3c4cf6c213e19c68ba28fce65466912ed3bf7d8b3210fbb
x86_64_v2 nodejs24-full-i18n-24.21.0-1.el10_2.x86_64_v2.rpm 59c57ba3bbf6ade56fe154025ce8727330cf5c89237ee8c064d125493834c371
x86_64_v2 nodejs24-24.21.0-1.el10_2.x86_64_v2.rpm 852b88bc1f3757e93d4f4ea60e7e41ec80bbac68188c15fd3e3141c23247cbec
x86_64_v2 nodejs24-libs-24.21.0-1.el10_2.x86_64_v2.rpm ec3ca4373fa8f0d271200a6587c6baa8584f1f62f4e9d4c5918231c6260d5d40
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.