[ALSA-2026:41947] Important: nodejs:22 security, bug fix, and enhancement update
Type:
security
Severity:
important
Release date:
2026-07-21
Description:
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) * undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151) * undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678) * undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733) * undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525) * nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619) * nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930) * nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935) * nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933) * nodejs: Node.js: Certification validation bypass in TLS host verification (CVE-2026-48934) * Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency (CVE-2026-48928) * nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling (CVE-2026-48615) * nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch (CVE-2026-48618) Bug Fix(es) and Enhancement(s): * nodejs:22/nodejs: Rebase to the latest Node.js 22 release [almalinux-8] (JIRA:AlmaLinux-176170) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 npm-10.9.8-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.aarch64.rpm 1b71bd6737533a7f78818c47bec4080230d33b60cf1f4d9f42a17cf054e558c0
aarch64 nodejs-devel-22.23.1-1.module_el8.10.0+4231+1bf2f855.aarch64.rpm 4a08c157216ff725b87e4bfb6b1e49640f18297d33f4859dc5edbf9d929057f2
aarch64 nodejs-22.23.1-1.module_el8.10.0+4231+1bf2f855.aarch64.rpm 4fb2352bbeff681ec41a2717996d98a24085c4c48574ec21ebe0c2829793da63
aarch64 nodejs-libs-22.23.1-1.module_el8.10.0+4231+1bf2f855.aarch64.rpm b34a4b25008a159e31b2784d4b23a1a84e9f8bebac5b04c27af07ee6da358cf2
aarch64 nodejs-full-i18n-22.23.1-1.module_el8.10.0+4231+1bf2f855.aarch64.rpm c55438f9f1171dae1d8c5e99147aa8e3337f426d15b7d888201a7af3d806bd88
aarch64 v8-12.4-devel-12.4.254.21-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.aarch64.rpm fad15502be5ffa80c4708dfe28fb53cc9824c7986afe0de3a5b203273ecc02c5
noarch nodejs-nodemon-3.0.1-1.module_el8.10.0+3956+47c9ee9f.noarch.rpm 021150406b73938423f86035275d5036c2cb0970af2ba79e22c19ead5527d763
noarch nodejs-packaging-bundler-2021.06-6.module_el8.10.0+4158+e796f37f.noarch.rpm 95549e780e9ad76b8e49f9c9db940d99cb8260f37e3d9cf05df2baaf6182e412
noarch nodejs-packaging-2021.06-6.module_el8.10.0+4158+e796f37f.noarch.rpm aaede6e40164690ca8a8b2229ad4ad4e0faea8ce4f2d6cfb3358572d8576dace
noarch nodejs-docs-22.23.1-1.module_el8.10.0+4231+1bf2f855.noarch.rpm d1e0fef2605d0ed0b4f8f22c16eb7a3338a7b99a35bc064eb6c66142b727c052
ppc64le nodejs-full-i18n-22.23.1-1.module_el8.10.0+4231+1bf2f855.ppc64le.rpm 49efe59fa98e0afefcfa74a1d185f036feca07b56fd9d253cc82de1c81a18d3a
ppc64le nodejs-libs-22.23.1-1.module_el8.10.0+4231+1bf2f855.ppc64le.rpm 5de919aaa31bcd636062b91289517194ea1024d2f7e17393c67392c69adec0be
ppc64le npm-10.9.8-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.ppc64le.rpm 8aa0f565200d91df503ea17cf2e2dbe25fdd4064492e8ac45e085e45abfb2c91
ppc64le nodejs-22.23.1-1.module_el8.10.0+4231+1bf2f855.ppc64le.rpm 9cac3bddcf0cfeb59ea37fc4a5282dfb3a6d864cf44f17eb2c5a236e74944f20
ppc64le nodejs-devel-22.23.1-1.module_el8.10.0+4231+1bf2f855.ppc64le.rpm a718472cb48196e1222bac5bd5be0b20d026dae6f08f36e54896a381bfed4af3
ppc64le v8-12.4-devel-12.4.254.21-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.ppc64le.rpm c080dfbd702dd1c8b0ab52cd0d2203813c1db1746b5e327cfcb24144ff8a2a6e
s390x v8-12.4-devel-12.4.254.21-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.s390x.rpm 21cdd65380d77949b7218c2131fed44fe68eeade1f334378e7eb200eb85fc0e9
s390x npm-10.9.8-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.s390x.rpm 54440347f9b4b6d3638962b510ef4a9d75908a3cd54e1447b02f9d808ed9811b
s390x nodejs-22.23.1-1.module_el8.10.0+4231+1bf2f855.s390x.rpm 87d4c10642bfcdf520104e594e4ccc1af41a4caa28b46447aab9c0208653d4a6
s390x nodejs-libs-22.23.1-1.module_el8.10.0+4231+1bf2f855.s390x.rpm 8bae4514f52ef01c9268f063267408cc2878128ee6fc086bac484403b4f05d09
s390x nodejs-full-i18n-22.23.1-1.module_el8.10.0+4231+1bf2f855.s390x.rpm a69ce8fa82a95c7a17d69ab74bb101299cc83fa0a7abc35fb6500ac7264ef30f
s390x nodejs-devel-22.23.1-1.module_el8.10.0+4231+1bf2f855.s390x.rpm c55f6c1b272f554db16f1dbd0a33ecbbccbc56ac5623691e386923ab860fe473
x86_64 nodejs-devel-22.23.1-1.module_el8.10.0+4231+1bf2f855.x86_64.rpm 0c800be04a19ed295ef5706730816583c680183fdd2e4061ca2c22a87bc7684c
x86_64 nodejs-22.23.1-1.module_el8.10.0+4231+1bf2f855.x86_64.rpm 1ce5d7869e90bedb6821cfdd92fb18cb9c2733f094c75bb3487327a84edb8079
x86_64 nodejs-libs-22.23.1-1.module_el8.10.0+4231+1bf2f855.x86_64.rpm 29c47164fcd318ffd6c21a322b15ab44f458c6284ccb4c48e68be1af45bb0e3e
x86_64 nodejs-full-i18n-22.23.1-1.module_el8.10.0+4231+1bf2f855.x86_64.rpm 7b2f41f31036d829f2f2f2077c7ad7438ee9e2ddfb6eda2514796d48b3e723cf
x86_64 npm-10.9.8-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.x86_64.rpm 870aadf427e6479693259a73abc85a94c0f98e6d2bf1f039fbb9b967542e827c
x86_64 v8-12.4-devel-12.4.254.21-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.x86_64.rpm e42d4c46059e3d7593e04d4cd5aa9e9525997d2f5c16a1c57deee087342eaebb
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.