RHSA-2026:52841: Important: nodejs-nodemon security update
Important: nodejs-nodemon security update
Other sources
Simple monitor script for use during development of a node.js app. For use during development of a node.js based application. nodemon will watch the files in the directory in which nodemon was started, and if any files change, nodemon will automatically restart your node application. nodemon does not require any changes to your code or method of development. nodemon simply wraps your node application and keeps an eye on any files that have changed. Remember that nodemon is a replacement wrapper for node, think of it as replacing the word "node" on the command line when you run your script.Security Fix(es): brace-expansion: brace-expansion: Denial of Service via unbounded intermediate arrays (CVE-2026-69152) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nodejs-nodemonto a version that resolves this vulnerability.Fixed in 3.1.14-3.el10_2 - Upgrade
Upgrade
nodemonto a version that resolves this vulnerability.Patch CVE-2026-69152
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:52841?
The severity of RHSA-2026:52841 is rated as high with a score of 7.
What issue does RHSA-2026:52841 address?
RHSA-2026:52841 addresses a security update for nodejs-nodemon, a simple monitor script for Node.js applications.
How do I fix RHSA-2026:52841?
To fix RHSA-2026:52841, update nodejs-nodemon to the latest version provided in the security update.
What software is affected by RHSA-2026:52841?
RHSA-2026:52841 affects multiple versions of Red Hat Enterprise Linux, including for x86_64, Power, and IBM z Systems.
When was RHSA-2026:52841 published?
RHSA-2026:52841 was published on August 10, 2026.