RHSA-2026:52394: Important: nodejs-nodemon security update
Important: nodejs-nodemon security update
Other sources
Simple monitor script for use during development of a node.js app. For use during development of a node.js based application. nodemon will watch the files in the directory in which nodemon was started, and if any files change, nodemon will automatically restart your node application. nodemon does not require any changes to your code or method of development. nodemon simply wraps your node application and keeps an eye on any files that have changed. Remember that nodemon is a replacement wrapper for node, think of it as replacing the word "node" on the command line when you run your script.Security Fix(es): brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nodejs-nodemonto a version that resolves this vulnerability.Fixed in 3.1.14-2.el10_0
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:52394?
The severity of RHSA-2026:52394 is classified as high with a score of 7.
How do I fix RHSA-2026:52394?
To fix RHSA-2026:52394, you need to update the nodejs-nodemon package to the latest version provided by Red Hat.
What vulnerabilities does RHSA-2026:52394 address?
RHSA-2026:52394 addresses security vulnerabilities found in the nodejs-nodemon package used for monitoring Node.js applications.
Which systems are affected by RHSA-2026:52394?
RHSA-2026:52394 affects Red Hat Enterprise Linux on various architectures including ARM 64, Power, and x86_64.
Is RHSA-2026:52394 critical for production environments?
Yes, given its high severity, it is crucial to apply the update from RHSA-2026:52394 in production environments to mitigate potential security risks.