Back to Security Advisories
High 2026-07-29

Nodejs:24 Security Update — AlmaLinux 8 (ALSA-2026:47060)

AlmaLinux 8

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) * tar: Node-tar: Denial of Service via malforme…

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

* brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
* tar: Node-tar: Denial of Service via malforme…

Type:
security

Severity:
important

Release date:
2026-07-29

Description:
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

* brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
* tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
* tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 nodejs-24.18.0-2.module_el8.10.0+4237+cde4efc3.aarch64.rpm 16cd626340efca5a6ced20a058b00259ddd931bb856e7eb52fdd772154828531
aarch64 nodejs-devel-24.18.0-2.module_el8.10.0+4237+cde4efc3.aarch64.rpm 700f8788ebf075ac8e25411687e6088e722793e9a8ac63a35c7416ef084b1c33
aarch64 nodejs-libs-24.18.0-2.module_el8.10.0+4237+cde4efc3.aarch64.rpm 9e0368ee0eeed36148904205abd939a87a2f8ef69edf2f4f4d46c60453f9aea5
aarch64 v8-13.6-devel-13.6.233.17-1.24.18.0.2.module_el8.10.0+4237+cde4efc3.aarch64.rpm a09234bfa2bdcb2e922909ab6d7a57d0e74ad7711b32970d564eb26fb38e84cc
aarch64 nodejs-full-i18n-24.18.0-2.module_el8.10.0+4237+cde4efc3.aarch64.rpm f1b2c6a8e2d7a8f0d4ca679d85a6b2a8fb79251efd5a2059c36e8d564bd534e4
noarch nodejs-packaging-2021.06-6.module_el8.10.0+4086+70facd4a.noarch.rpm 318c493f93f2190506361306b5759e5e65eee18e3a8d85b195c800d8b7064bc0
noarch npm-11.16.0-1.24.18.0.2.module_el8.10.0+4237+cde4efc3.noarch.rpm 361d4a0fa19754d400849ec9f2599c5fbc8b47bf2f2fd22725a4a281f3e0bd3a
noarch nodejs-docs-24.18.0-2.module_el8.10.0+4237+cde4efc3.noarch.rpm 87c5f901ba1b1de363cd9029fad9c8a049fdb3b57bc8f9e54d4f66d135a0fbc4
noarch nodejs-packaging-bundler-2021.06-6.module_el8.10.0+4086+70facd4a.noarch.rpm f4b4a25dc07327deb51619715aae6bd35d22e29ccfc97141c0b61de3a1995eee
noarch nodejs-nodemon-3.1.14-1.module_el8.10.0+4237+cde4efc3.noarch.rpm ffdf1650bda43312ebf24f69c1f4d78eca83929db5af5f3bead0321333812824
ppc64le nodejs-full-i18n-24.18.0-2.module_el8.10.0+4237+cde4efc3.ppc64le.rpm 5daa1e37f47e95795009d5033be0c9311345577f8377eb861fe29f749ddb69d1
ppc64le nodejs-24.18.0-2.module_el8.10.0+4237+cde4efc3.ppc64le.rpm 5f2122cd38056bfc7365eea5ff890e6678bc58296d7adda6e9ea4c943891587a
ppc64le nodejs-devel-24.18.0-2.module_el8.10.0+4237+cde4efc3.ppc64le.rpm 8b677eabf0fea40f787b8365e3254925368483622317d92816976593264969f1
ppc64le v8-13.6-devel-13.6.233.17-1.24.18.0.2.module_el8.10.0+4237+cde4efc3.ppc64le.rpm a0ec8162ad91aeffaf06592ff878550df04cc6899a8d80b5a36abb2a86dbd13f
ppc64le nodejs-libs-24.18.0-2.module_el8.10.0+4237+cde4efc3.ppc64le.rpm f3836845f9e1ff2e4c4cf6861fdb70f9c1b0c966b9b3c02252f64d151f86d86f
s390x nodejs-devel-24.18.0-2.module_el8.10.0+4237+cde4efc3.s390x.rpm 5fe9df3338f9436e3beebaf3002e5fdf45063e74404d9a41bec7d30e3d16c2b3
s390x nodejs-full-i18n-24.18.0-2.module_el8.10.0+4237+cde4efc3.s390x.rpm a8d8dabee47f6c1bd0c8eb351a6cb24a71ce2b7628e591a7c4400ef961b93b97
s390x v8-13.6-devel-13.6.233.17-1.24.18.0.2.module_el8.10.0+4237+cde4efc3.s390x.rpm b18e83a2b09bd776d60559e587ea8645023c87ce0fdf3548c7f6b548aae0c485
s390x nodejs-libs-24.18.0-2.module_el8.10.0+4237+cde4efc3.s390x.rpm d0a744465ec55d4e3be33aab5413546502ca87383b1555d1a7c6a85c120e827a
s390x nodejs-24.18.0-2.module_el8.10.0+4237+cde4efc3.s390x.rpm fee5b18b00a345207a3d343ea00f3cd825b35de54efc2b4e9f131dfc200793d4
x86_64 nodejs-full-i18n-24.18.0-2.module_el8.10.0+4237+cde4efc3.x86_64.rpm 3e0ee4e5a158831be61f2e044f6bcc513bd0ca7d7c15725d7ef818c8ecdd2246
x86_64 nodejs-libs-24.18.0-2.module_el8.10.0+4237+cde4efc3.x86_64.rpm 73830f99efe84ff31c2fcab612f37085118e68edfbbdd3043151e21e461a0c40
x86_64 nodejs-devel-24.18.0-2.module_el8.10.0+4237+cde4efc3.x86_64.rpm 73bc1435502fc5624ff76531ed8110290c815da742d0bb6503794e7f9e306ff2
x86_64 v8-13.6-devel-13.6.233.17-1.24.18.0.2.module_el8.10.0+4237+cde4efc3.x86_64.rpm e8a63d89060bc4b26b2474dbf76beb8508bc6001b654149841e21a1b7c20a916
x86_64 nodejs-24.18.0-2.module_el8.10.0+4237+cde4efc3.x86_64.rpm efa9c04700ed3bbd9aba75fbf04afd09116938f3773adb519a0f334a6386f4cf

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

More Information

Check your system for vulnerabilities

Selecciona tu producto y sistema operativo para ver los comandos de corrección exactos que se aplican a ti.

Check Your System