RHSA-2026:61376: Important: nodejs22 security update
Important: nodejs22 security update
Other sources
Node.js is a platform built on Chrome's JavaScript runtime \ for easily building fast, scalable network applications. \ Node.js uses an event-driven, non-blocking I/O model that \ makes it lightweight and efficient, perfect for data-intensive \ real-time applications that run across distributed devices.Security Fix(es): nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw (CVE-2026-58043) nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks (CVE-2026-56846) nodejs: Node.js: Heap-use-after-free in HTTP/2 handling can lead to denial of service (CVE-2026-56848) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nodejs22to a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2 - Upgrade
Upgrade
redhat/nodejsto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2 - Upgrade
Upgrade
redhat/nodejs-debuginfoto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2 - Upgrade
Upgrade
redhat/nodejs-develto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2 - Upgrade
Upgrade
redhat/nodejs-docsto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2 - Upgrade
Upgrade
redhat/nodejs-full-i18nto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2 - Upgrade
Upgrade
redhat/nodejs-libsto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2 - Upgrade
Upgrade
redhat/nodejs-libs-debuginfoto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2 - Upgrade
Upgrade
redhat/nodejs-npmto a version that resolves this vulnerability.Fixed in 10.9.8-1.22.23.2.1.el10_2 - Upgrade
Upgrade
redhat/nodejs22-debuginfoto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2 - Upgrade
Upgrade
redhat/nodejs22-debugsourceto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2 - Upgrade
Upgrade
redhat/nodejsto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2.aa - Upgrade
Upgrade
redhat/nodejs-debuginfoto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2.aa - Upgrade
Upgrade
redhat/nodejs-develto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2.aa - Upgrade
Upgrade
redhat/nodejs-full-i18nto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2.aa - Upgrade
Upgrade
redhat/nodejs-libsto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2.aa - Upgrade
Upgrade
redhat/nodejs-libs-debuginfoto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2.aa - Upgrade
Upgrade
redhat/nodejs-npmto a version that resolves this vulnerability.Fixed in 10.9.8-1.22.23.2.1.el10_2.aa - Upgrade
Upgrade
redhat/nodejs22-debuginfoto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2.aa - Upgrade
Upgrade
redhat/nodejs22-debugsourceto a version that resolves this vulnerability.Fixed in 22.23.2-1.el10_2.aa
Event History
Frequently Asked Questions
Which deployments are most exposed to the remotely triggered issues?
Node.js deployments that handle HTTP/2 traffic are relevant to the two HTTP/2 flaws. One can cause remote memory exhaustion through retained header blocks, and the other is a heap-use-after-free that can lead to denial of service.
What capability does an attacker need for the filesystem-access issue?
The available information identifies an enforcement flaw in the Node.js Permission Model that can result in unauthorized filesystem access. It does not specify the attacker’s required access level, affected Permission Model settings, or exploitation conditions.
Which installed components should be included when applying the update?
The advisory lists redhat/nodejs, redhat/nodejs-libs, redhat/nodejs-npm, redhat/nodejs-devel, redhat/nodejs-full-i18n, and associated debuginfo packages, including redhat/nodejs22-debuginfo. Ensure the Node.js package set installed on the affected system is updated consistently.