RHSA-2026:52399: Important: nodejs:22 security update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151) nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933) nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling (CVE-2026-48615) nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch (CVE-2026-48618) brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149) tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874) tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/nodejsto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b - Upgrade
Upgrade
redhat/nodejs-nodemonto a version that resolves this vulnerability.Fixed in 3.1.14-1.module+el9.6.0+24604+449f851b - Upgrade
Upgrade
redhat/nodejs-packagingto a version that resolves this vulnerability.Fixed in 2021.06-4.module+el9.6.0+23473+45664c2d - Upgrade
Upgrade
redhat/nodejs-docsto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b - Upgrade
Upgrade
redhat/nodejs-packaging-bundlerto a version that resolves this vulnerability.Fixed in 2021.06-4.module+el9.6.0+23473+45664c2d - Upgrade
Upgrade
redhat/nodejs-debuginfoto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b - Upgrade
Upgrade
redhat/nodejs-debugsourceto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b - Upgrade
Upgrade
redhat/nodejs-develto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b - Upgrade
Upgrade
redhat/nodejs-full-i18nto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b - Upgrade
Upgrade
redhat/nodejs-libsto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b - Upgrade
Upgrade
redhat/nodejs-libs-debuginfoto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b - Upgrade
Upgrade
redhat/npmto a version that resolves this vulnerability.Fixed in 10.9.8-1.22.23.1.2.module+el9.6.0+24604+449f851b - Upgrade
Upgrade
redhat/v8to a version that resolves this vulnerability.Fixed in 12.4-devel-12.4.254.21-1.22.23.1.2.module+el9.6.0+24604+449f851b - Upgrade
Upgrade
redhat/nodejsto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b.aa - Upgrade
Upgrade
redhat/nodejs-debuginfoto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b.aa - Upgrade
Upgrade
redhat/nodejs-debugsourceto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b.aa - Upgrade
Upgrade
redhat/nodejs-develto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b.aa - Upgrade
Upgrade
redhat/nodejs-full-i18nto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b.aa - Upgrade
Upgrade
redhat/nodejs-libsto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b.aa - Upgrade
Upgrade
redhat/nodejs-libs-debuginfoto a version that resolves this vulnerability.Fixed in 22.23.1-2.module+el9.6.0+24604+449f851b.aa - Upgrade
Upgrade
redhat/npmto a version that resolves this vulnerability.Fixed in 10.9.8-1.22.23.1.2.module+el9.6.0+24604+449f851b.aa - Upgrade
Upgrade
redhat/v8to a version that resolves this vulnerability.Fixed in 12.4-devel-12.4.254.21-1.22.23.1.2.module+el9.6.0+24604+449f851b.aa
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:52399?
The severity of RHSA-2026:52399 is classified as Important.
What vulnerabilities are addressed in RHSA-2026:52399?
RHSA-2026:52399 addresses vulnerabilities such as CVE-2026-42338 related to Cross-site scripting and Denial of Service.
How do I fix RHSA-2026:52399?
To fix RHSA-2026:52399, you need to update to the latest versions of the affected Node.js packages.
Which versions of Node.js are affected by RHSA-2026:52399?
RHSA-2026:52399 affects multiple versions of Red Hat's Node.js packages including nodejs, nodejs-libs, and npm.
Is there a workaround for the issues in RHSA-2026:52399?
There is no recommended workaround for the vulnerabilities in RHSA-2026:52399; updating is the best option.