- What: Security update for nodejs:22
- Impact: Addresses security vulnerabilities in Red Hat Enterprise Linux
Red Hat Product Errata RHSA-2026:35892 - Security Advisory Issued: 2026-07-06 Updated: 2026-07-06 RHSA-2026:35892 - Security Advisory Overview Updated Packages Synopsis Important: nodejs:22 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the nodejs:22 module is now available for Red Hat Enterprise Linux 9. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151) undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678) undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733) undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525) nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619) nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930) nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935) nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933) nodejs: Node.js: Certification validation bypass in TLS host verification (CVE-2026-48934) Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency (CVE-2026-48928) nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling (CVE-2026-48615) nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch (CVE-2026-48618) Bug Fix(es) and Enhancement(s): nodejs:22/nodejs: Rebase to the latest Node.js 22 release [rhel-9.8.z] (JIRA:RHEL-186622) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 9 x86_64 Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 x86_64 Red Hat Enterprise Linux for IBM z Systems 9 s390x Red Hat Enterprise Linux for IBM z Systems - Extended Update Support 9.8 s390x Red Hat Enterprise Linux for Power, little endian 9 ppc64le Red Hat Enterprise Linux for Power, little endian - Extended Update Support 9.8 ppc64le Red Hat Enterprise Linux for ARM 64 9 aarch64 Red Hat Enterprise Linux for ARM 64 - Extended Update Support 9.8 aarch64 Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions 9.8 ppc64le Red Hat Enterprise Linux for x86_64 - Update Services for SAP Solutions 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - 4 years of updates 9.8 aarch64 Red Hat Enterprise Linux for IBM z Systems - 4 years of updates 9.8 s390x Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 9.8 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 9.8 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 9.8 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 9.8 s390x Fixes BZ - 2476810 - CVE-2026-42338 ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input BZ - 2489980 - CVE-2026-12151 undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames BZ - 2490000 - CVE-2026-9678 undici: Undici: Information disclosure due to improper cache-control header parsing BZ - 2490006 - CVE-2026-6733 undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. BZ - 2490008 - CVE-2026-11525 undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header BZ - 2493325 - CVE-2026-48619 nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames BZ - 2493326 - CVE-2026-48930 nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling BZ - 2493329 - CVE-2026-48935 nodejs: Node.js: Unauthorized file metadata modification BZ - 2493331 - CVE-2026-48933 nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() BZ - 2493332 - CVE-2026-48934 nodejs: Node.js: Certification validation bypass in TLS host verification BZ - 2493333 - CVE-2026-48928 Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency BZ - 2493335 - CVE-2026-48615 nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling BZ - 2493337 - CVE-2026-48618 nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch RHEL-186622 - nodejs:22/nodejs: Rebase to the latest Node.js 22 release [rhel-9.8.z] CVEs CVE-2026-6733 CVE-2026-9678 CVE-2026-11525 CVE-2026-12151 CVE-2026-42338 CVE-2026-48615 CVE-2026-48618 CVE-2026-48619 CVE-2026-48928 CVE-2026-48930 CVE-2026-48933 CVE-2026-48934 CVE-2026-48935 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 9 SRPM nodejs-22.23.1-1.module+el9.8.0+24457+996af7aa.src.rpm SHA-256: 77567781151326ee2fd43cd2b01bf2011a4877faf7aa82110f3eb4dec44f91c4 nodejs-nodemon-3.0.1-1.module+el9.8.0+24156+bb41d456.src.rpm SHA-256: 0851596e9256a713cc69d0bdf2b4dee39d41d8ccbff37d0b4e44067fab3ec731 nodejs-packaging-2021.06-6.module+el9.8.0+24156+bb41d456.src.rpm SHA-256: 7d1e9988b726d74470a1a1bfd2a6feab76316edfffe5d4807dca5ae4fd23ea1f x86_64 nodejs-docs-22.23.1-1.module+el9.8.0+24457+996af7aa.noarch.rpm SHA-256: 6f5d6b98f4ee15a9609626f57d89eb0b19cf9fd8d16a29662f4559f5b54491e6 nodejs-nodemon-3.0.1-1.module+el9.8.0+24156+bb41d456.noarch.rpm SHA-256: f9266714fb368f0270485a743e83ed7c9a8b5637ce0270c70559ff743d12009e nodejs-packaging-2021.06-6.module+el9.8.0+24156+bb41d456.noarch.rpm SHA-256: 6c80cf85e6c3608c2a3bee9b0e687d713797a944ff352d14dbc2765c6beab1da nodejs-packaging-bundler-2021.06-6.module+el9.8.0+24156+bb41d456.noarch.rpm SHA-256: 69c62d097a744fb130d753267045dc64009e6f7071a983d9d3a112a18daf1ad6 nodejs-docs-22.23.1-1.module+el9.8.0+24457+996af7aa.noarch.rpm SHA-256: 6f5d6b98f4ee15a9609626f57d89eb0b19cf9fd8d16a29662f4559f5b54491e6 nodejs-nodemon-3.0.1-1.module+el9.8.0+24156+bb41d456.noarch.rpm SHA-256: f9266714fb368f0270485a743e83ed7c9a8b5637ce0270c70559ff743d12009e nodejs-packaging-2021.06-6.module+el9.8.0+24156+bb41d456.noarch.rpm SHA-256: 6c80cf85e6c3608c2a3bee9b0e687d713797a944ff352d14dbc2765c6beab1da nodejs-packaging-bundler-2021.06-6.module+el9.8.0+24156+bb41d456.noarch.rpm SHA-256: 69c62d097a744fb130d753267045dc64009e6f7071a983d9d3a112a18daf1ad6 nodejs-docs-22.23.1-1.module+el9.8.0+24457+996af7aa.noarch.rpm SHA-256: 6f5d6b98f4ee15a9609626f57d89eb0b19cf9fd8d16a29662f4559f5b54491e6 nodejs-nodemon-3.0.1-1.module+el9.8.0+24156+bb41d456.noarch.rpm SHA-256: f9266714fb368f0270485a743e83ed7c9a8b5637ce0270c70559ff743d12009e nodejs-packaging-2021.06-6.module+el9.8.0+24156+bb41d456.noarch.rpm SHA-256: 6c80cf85e6c3608c2a3bee9b0e687d713797a944ff352d14dbc2765c6beab1da nodejs-packaging-bundler-2021.06-6.module+el9.8.0+24156+bb41d456.noarch.rpm SHA-256: 69c62d097a744fb130d753267045dc64009e6f7071a983d9d3a112a18daf1ad6 nodejs-22.23.1-1.module+el9.8.0+24457+996af7aa.x86_64.rpm SHA-256: 0687f854e38bcb7382884a786f9d728afc1fd95c4d904c76a2212a497cba0d66 nodejs-debuginfo-22.23.1-1.module+el9.8.0+24457+996af7aa.x86_64.rpm SHA-256: 9eb10ec8450ca435cdba37364c0d1154bda135d9bb65eb25d34ee1bf29af2d92 nodejs-debugsource-22.23.1-1.module+el9.8.0+24457+996af7aa.x86_64.rpm SHA-256: e9dddaf9c28d25d58eb9b30952099b8167a3503343d06e0041a8175db9fa6edc nodejs-devel-22.23.1-1.module+el9.8.0+24457+996af7aa.x86_64.rpm SHA-256: 7271307daced063b3785688b6db3befee3cbff910ce56544a5cdbfe8956164af nodejs-docs-22.23.1-1.module+el9.8.0+24457+996af7aa.noarch.rpm SHA-256: 6f5d6b98f4ee15a9609626f57d89eb0b19cf9fd8d16a29662f4559f5b54491e6 nodejs-full-i18n-22.23.1-1.module+el9.8.0+24457+996af7aa.x86_64.rpm SHA-256: 0f3ff55b2177f88a93a4a4899e051d472b0ced2380784f0e8260ffac186c4728 nodejs-libs-22.23.1-1.module+el9.8.0+24457+996af7aa.x86_64.rpm SHA-256: ae5b162e321ba768499dbfad5f7608a4cc4dc49f9b420df7aabb1c19ef90522c nodejs-libs-debuginfo-22.23.1-1.module+el9.8.0+24457+996af7aa.x86_64.rpm SHA-256: 700457facb22d2a8ce641fa70363219ca170ccf8bededf90249e9edb282360d9 nodejs-nodemon-3.0.1-1.module+el9.8.0+24156+bb41d456.noarch.rpm SHA-256: f9266714fb368f0270485a743e83ed7c9a8b5637ce0270c70559ff743d12009e nodejs-packaging-2021.06-6.module+el9.8.0+24156+bb41d456.noarch.rpm SHA-256: 6c80cf85e6c3608c2a3bee9b0e687d713797a944ff352d14dbc2765c6beab1da nodejs-packaging-bundler-2021.06-6.module+el9.8.0+24156+bb41d456.noarch.rpm SHA-256: 69c62d097a744fb130d753267045dc64009e6f7071a983d9d3a112a18daf1ad6 npm-10.9.8-1.22.23.1.1.module+el9.8.0+24457+996af7aa.x86_64.rpm SHA-256: eb35eac7022ac186842d85ad250713b8a90010e66f485944d0cb6c6d77a8a53b v8-12.4-devel-12.4.254.21-1.22.23.1.1.module+el9.8.0+24457+996af7aa.x86_64.rpm SHA-256: 3827e9e61f2371a39469d99f5163ffe9dcbdc14d29bc5da7a8eb5efc0e3ca5de Red Hat Enterprise Linux for x86_64 - Extended Update Support 9.8 SRPM nodejs-22.23.1-1.module+el9.8.0+24457+996af7aa.src.rpm SHA-256: 77567781151326ee2fd43cd2b01bf20