- What: Security, bug fix, and enhancement update for nodejs24
- Impact: Red Hat Enterprise Linux 10 users affected
Red Hat Product Errata RHSA-2026:35841 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:35841 - Security Advisory Overview Updated Packages Synopsis Important: nodejs24 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for nodejs24 is now available for Red Hat Enterprise Linux 10. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices. Security Fix(es): ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151) undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678) undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733) undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525) undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy (CVE-2026-9697) undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing (CVE-2026-6734) nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619) nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930) nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935) nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933) nodejs: Node.js: Certification validation bypass in TLS host verification (CVE-2026-48934) Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency (CVE-2026-48928) nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling (CVE-2026-48615) nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch (CVE-2026-48618) Bug Fix(es) and Enhancement(s): nodejs24: Rebase to the latest Node.js 24 release [rhel-10.2.z] (JIRA:RHEL-186582) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 10 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 x86_64 Red Hat Enterprise Linux for IBM z Systems 10 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 10.2 s390x Red Hat Enterprise Linux for Power, little endian 10 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 10.2 ppc64le Red Hat Enterprise Linux for ARM 64 10 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 10.2 aarch64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 10.2 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 10.2 s390x Red Hat Enterprise Linux for Power, little endian - 4 years of support 10.2 ppc64le Red Hat Enterprise Linux for x86_64 - 4 years of updates 10.2 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 10.2 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 10.2 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 10.2 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 10.2 s390x Fixes BZ - 2476810 - CVE-2026-42338 ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input BZ - 2489980 - CVE-2026-12151 undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames BZ - 2490000 - CVE-2026-9678 undici: Undici: Information disclosure due to improper cache-control header parsing BZ - 2490006 - CVE-2026-6733 undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. BZ - 2490008 - CVE-2026-11525 undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header BZ - 2490018 - CVE-2026-9697 undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy BZ - 2490024 - CVE-2026-6734 undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing BZ - 2493325 - CVE-2026-48619 nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames BZ - 2493326 - CVE-2026-48930 nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling BZ - 2493329 - CVE-2026-48935 nodejs: Node.js: Unauthorized file metadata modification BZ - 2493331 - CVE-2026-48933 nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() BZ - 2493332 - CVE-2026-48934 nodejs: Node.js: Certification validation bypass in TLS host verification BZ - 2493333 - CVE-2026-48928 Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency BZ - 2493335 - CVE-2026-48615 nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling BZ - 2493337 - CVE-2026-48618 nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch RHEL-186582 - nodejs24: Rebase to the latest Node.js 24 release [rhel-10.2.z] CVEs CVE-2026-6733 CVE-2026-6734 CVE-2026-9678 CVE-2026-9697 CVE-2026-11525 CVE-2026-12151 CVE-2026-42338 CVE-2026-48615 CVE-2026-48618 CVE-2026-48619 CVE-2026-48928 CVE-2026-48930 CVE-2026-48933 CVE-2026-48934 CVE-2026-48935 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 10 SRPM nodejs24-24.18.0-1.el10_2.src.rpm SHA-256: 0e0ef13f46cd1b274ced8138aa22dd8fc4e0061e57e9bcd76d0bcf2b1bc7c1e6 x86_64 nodejs24-24.18.0-1.el10_2.x86_64.rpm SHA-256: 9c23623f2e73c9ef35c7a0b194416561cc3d9bbcb8f8f325ec63f7c7601db99b nodejs24-debuginfo-24.18.0-1.el10_2.x86_64.rpm SHA-256: 0638cbc0a6c3751e4a8beef36f5b30832d4bd6da2da4ed926f269ea35be6d3cc nodejs24-debugsource-24.18.0-1.el10_2.x86_64.rpm SHA-256: 5778d497549164059f47506448d6b877f0fd4efb6c32a63fb10a262c87baabcc nodejs24-devel-24.18.0-1.el10_2.x86_64.rpm SHA-256: fbf3e14dabd8dbfff2fb2b86917716806463640101fb2b8b23510bc04e0ec932 nodejs24-docs-24.18.0-1.el10_2.noarch.rpm SHA-256: f2d8b84a6a0051e5122bcbb19c90cb7e613a4dd77f637a52a94f3bd130d87a0c nodejs24-full-i18n-24.18.0-1.el10_2.x86_64.rpm SHA-256: d13b765e328aa46b63e52e2050e58ce44451adf7f6659d5ef61df12457d9874b nodejs24-libs-24.18.0-1.el10_2.x86_64.rpm SHA-256: d4f1d48592376c1e0410a844631ecbdbc9999712e932e42d210ddada77903159 nodejs24-libs-debuginfo-24.18.0-1.el10_2.x86_64.rpm SHA-256: 5fe70933eee68a7785c8393f86654b6654836f53d7af678f5023c9b2eb65f3c7 nodejs24-npm-11.16.0-1.24.18.0.1.el10_2.noarch.rpm SHA-256: f24fafb80fb9332d286a5f250ea27c8e55c7801d473c21c81e4ae268e877a007 Red Hat Enterprise Linux for x86_64 - Extended Update Support 10.2 SRPM nodejs24-24.18.0-1.el10_2.src.rpm SHA-256: 0e0ef13f46cd1b274ced8138aa22dd8fc4e0061e57e9bcd76d0bcf2b1bc7c1e6 x86_64 nodejs24-24.18.0-1.el10_2.x86_64.rpm SHA-256: 9c23623f2e73c9ef35c7a0b194416561cc3d9bbcb8f8f325ec63f7c7601db99b nodejs24-debuginfo-24.18.0-1.el10_2.x86_64.rpm SHA-256: 0638cbc0a6c3751e4a8beef36f5b30832d4bd6da2da4ed926f269ea35be6d3cc nodejs24-debugsource-24.18.0-1.el10_2.x86_64.rpm SHA-256: 5778d497549164059f47506448d6b877f0fd4efb6c32a63fb10a262c87baabcc nodejs24-devel-24.18.0-1.el10_2.x86_64.rpm SHA-256: fbf3e14dabd8dbfff2fb2b86917716806463640101fb2b8b23510bc04e0ec932 nodejs24-docs-24.18.0-1.el10_2.noarch.rpm SHA-256: f2d8b84a6a0051e5122bcbb19c90cb7e613a4dd77f637a52a94f3bd130d87a0c nodejs24-full-i18n-24.18.0-1.el10_2.x86_64.rpm SHA-256: d13b765e328aa46b63e52e2050e58ce44451adf7f6659d5ef61df12457d9874b nodejs24-libs-24.18.0-1.el10_2.x86_64.rpm SHA-256: d4f1d48592376c1e0410a844631ecbdbc9999712e932e42d210ddada77903159 nodejs24-libs-debuginfo-24.18.0-1.el10_2.x86_64.rpm SHA-256: 5fe70933eee68a7785c8393f86654b6654836f53d7af678f5023c9b2eb65f3c7 nodejs24-npm-11.16.0-1.24.18.0.1.el10_2.noarch.rpm SHA-256: f24fafb80fb9332d286a5f250ea27c8e55c7801d473c21c81e4ae268e877a007 Red Hat Enterprise Linux for IBM z Systems 10 SRPM nodejs24-24.18.0-1.el10_2.src.rpm SHA-256: 0e0ef13f46cd1b274ced8138aa22dd8fc4e0061e57e9bcd76d0bcf2b1bc7c1e6 s390x nodejs24-24.18.0-1.el10_2.s390x.rpm SHA-256: 86d49ee15248e048ac12a5bf2561044fae10bb895401d8c338e4efc57aaabc3d nodejs24-debuginfo-24.18.0-1.el10_2.s390x.rpm SHA-256: 1af1072d8938b3c2e214a97ece24ea4a1dbb8933b5382590e0df9b543bab4b84 nodejs24-debugsource-24.18.0-1.el10_2.s390x.rpm SHA-256: c7b29cde267f7d96f06e98ccddc70ed741bd375995b016148d4b657ab27c6cd2 nodejs24-devel-24.18.0-1.el10_2.s390x.rpm SHA-256: 96c6cedd08f04c537504436acc5d42fd20b55e18400132dfb478578fe923a171 nodejs24-docs-24.18.0-1.el10_2.noarch.rpm SHA-256: f2d8b84a6a0051e5122bcbb19c90cb7e613a4dd77f637a52a94f3bd130d87a0c nodejs24-full-i18n-24.18.0-1.el10_2.s390x.rpm SHA-256: cf5751f58498cdb07870c1e395e5da3c71415a98dbe2ae3c14a80babe3eedad2 nodejs24-libs-24.18.0-1.el10_2.s390x.rpm SHA-256: 3245549d471d3a9567fc17b96ef299a80829eb37191ddfebc1715511c29bd59e nodejs24-libs-debuginfo-24.18.0