Back to Security Advisories
High 2026-07-21

Nodejs:22 Security Update — AlmaLinux 8 (ALSA-2026:41947)

AlmaLinux 8

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) * undici: undici: Denial of Service due to …

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)
* undici: undici: Denial of Service due to …

Type:
security

Severity:
important

Release date:
2026-07-21

Description:
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

* ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338)
* undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151)
* undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678)
* undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733)
* undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525)
* nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619)
* nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930)
* nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935)
* nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933)
* nodejs: Node.js: Certification validation bypass in TLS host verification (CVE-2026-48934)
* Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency (CVE-2026-48928)
* nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling (CVE-2026-48615)
* nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch (CVE-2026-48618)

Bug Fix(es) and Enhancement(s):

* nodejs:22/nodejs: Rebase to the latest Node.js 22 release [almalinux-8] (JIRA:AlmaLinux-176170)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Updated packages listed below:

Architecture Package Checksum
aarch64 npm-10.9.8-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.aarch64.rpm 1b71bd6737533a7f78818c47bec4080230d33b60cf1f4d9f42a17cf054e558c0
aarch64 nodejs-devel-22.23.1-1.module_el8.10.0+4231+1bf2f855.aarch64.rpm 4a08c157216ff725b87e4bfb6b1e49640f18297d33f4859dc5edbf9d929057f2
aarch64 nodejs-22.23.1-1.module_el8.10.0+4231+1bf2f855.aarch64.rpm 4fb2352bbeff681ec41a2717996d98a24085c4c48574ec21ebe0c2829793da63
aarch64 nodejs-libs-22.23.1-1.module_el8.10.0+4231+1bf2f855.aarch64.rpm b34a4b25008a159e31b2784d4b23a1a84e9f8bebac5b04c27af07ee6da358cf2
aarch64 nodejs-full-i18n-22.23.1-1.module_el8.10.0+4231+1bf2f855.aarch64.rpm c55438f9f1171dae1d8c5e99147aa8e3337f426d15b7d888201a7af3d806bd88
aarch64 v8-12.4-devel-12.4.254.21-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.aarch64.rpm fad15502be5ffa80c4708dfe28fb53cc9824c7986afe0de3a5b203273ecc02c5
noarch nodejs-nodemon-3.0.1-1.module_el8.10.0+3956+47c9ee9f.noarch.rpm 021150406b73938423f86035275d5036c2cb0970af2ba79e22c19ead5527d763
noarch nodejs-packaging-bundler-2021.06-6.module_el8.10.0+4158+e796f37f.noarch.rpm 95549e780e9ad76b8e49f9c9db940d99cb8260f37e3d9cf05df2baaf6182e412
noarch nodejs-packaging-2021.06-6.module_el8.10.0+4158+e796f37f.noarch.rpm aaede6e40164690ca8a8b2229ad4ad4e0faea8ce4f2d6cfb3358572d8576dace
noarch nodejs-docs-22.23.1-1.module_el8.10.0+4231+1bf2f855.noarch.rpm d1e0fef2605d0ed0b4f8f22c16eb7a3338a7b99a35bc064eb6c66142b727c052
ppc64le nodejs-full-i18n-22.23.1-1.module_el8.10.0+4231+1bf2f855.ppc64le.rpm 49efe59fa98e0afefcfa74a1d185f036feca07b56fd9d253cc82de1c81a18d3a
ppc64le nodejs-libs-22.23.1-1.module_el8.10.0+4231+1bf2f855.ppc64le.rpm 5de919aaa31bcd636062b91289517194ea1024d2f7e17393c67392c69adec0be
ppc64le npm-10.9.8-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.ppc64le.rpm 8aa0f565200d91df503ea17cf2e2dbe25fdd4064492e8ac45e085e45abfb2c91
ppc64le nodejs-22.23.1-1.module_el8.10.0+4231+1bf2f855.ppc64le.rpm 9cac3bddcf0cfeb59ea37fc4a5282dfb3a6d864cf44f17eb2c5a236e74944f20
ppc64le nodejs-devel-22.23.1-1.module_el8.10.0+4231+1bf2f855.ppc64le.rpm a718472cb48196e1222bac5bd5be0b20d026dae6f08f36e54896a381bfed4af3
ppc64le v8-12.4-devel-12.4.254.21-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.ppc64le.rpm c080dfbd702dd1c8b0ab52cd0d2203813c1db1746b5e327cfcb24144ff8a2a6e
s390x v8-12.4-devel-12.4.254.21-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.s390x.rpm 21cdd65380d77949b7218c2131fed44fe68eeade1f334378e7eb200eb85fc0e9
s390x npm-10.9.8-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.s390x.rpm 54440347f9b4b6d3638962b510ef4a9d75908a3cd54e1447b02f9d808ed9811b
s390x nodejs-22.23.1-1.module_el8.10.0+4231+1bf2f855.s390x.rpm 87d4c10642bfcdf520104e594e4ccc1af41a4caa28b46447aab9c0208653d4a6
s390x nodejs-libs-22.23.1-1.module_el8.10.0+4231+1bf2f855.s390x.rpm 8bae4514f52ef01c9268f063267408cc2878128ee6fc086bac484403b4f05d09
s390x nodejs-full-i18n-22.23.1-1.module_el8.10.0+4231+1bf2f855.s390x.rpm a69ce8fa82a95c7a17d69ab74bb101299cc83fa0a7abc35fb6500ac7264ef30f
s390x nodejs-devel-22.23.1-1.module_el8.10.0+4231+1bf2f855.s390x.rpm c55f6c1b272f554db16f1dbd0a33ecbbccbc56ac5623691e386923ab860fe473
x86_64 nodejs-devel-22.23.1-1.module_el8.10.0+4231+1bf2f855.x86_64.rpm 0c800be04a19ed295ef5706730816583c680183fdd2e4061ca2c22a87bc7684c
x86_64 nodejs-22.23.1-1.module_el8.10.0+4231+1bf2f855.x86_64.rpm 1ce5d7869e90bedb6821cfdd92fb18cb9c2733f094c75bb3487327a84edb8079
x86_64 nodejs-libs-22.23.1-1.module_el8.10.0+4231+1bf2f855.x86_64.rpm 29c47164fcd318ffd6c21a322b15ab44f458c6284ccb4c48e68be1af45bb0e3e
x86_64 nodejs-full-i18n-22.23.1-1.module_el8.10.0+4231+1bf2f855.x86_64.rpm 7b2f41f31036d829f2f2f2077c7ad7438ee9e2ddfb6eda2514796d48b3e723cf
x86_64 npm-10.9.8-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.x86_64.rpm 870aadf427e6479693259a73abc85a94c0f98e6d2bf1f039fbb9b967542e827c
x86_64 v8-12.4-devel-12.4.254.21-1.22.23.1.1.module_el8.10.0+4231+1bf2f855.x86_64.rpm e42d4c46059e3d7593e04d4cd5aa9e9525997d2f5c16a1c57deee087342eaebb

Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.

More Information

Check your system for vulnerabilities

Выберите продукт и операционную систему, чтобы увидеть точные команды исправления.

Check Your System