Red Hat Product Errata RHSA-2026:41947 - Security Advisory Issued: 2026-07-20 Updated: 2026-07-20 RHSA-2026:41947 - Security Advisory Overview Updated Packages Synopsis Important: nodejs:22 security, bug fix, and enhancement update Type/Severity Security Advisory: Important Red Hat Lightspeed patch analysis Identify and remediate systems affected by this advisory. View affected systems Topic An update for the nodejs:22 module is now available for Red Hat Enterprise Linux 8. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. Description Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input (CVE-2026-42338) undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames (CVE-2026-12151) undici: Undici: Information disclosure due to improper cache-control header parsing (CVE-2026-9678) undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. (CVE-2026-6733) undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header (CVE-2026-11525) nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames (CVE-2026-48619) nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling (CVE-2026-48930) nodejs: Node.js: Unauthorized file metadata modification (CVE-2026-48935) nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() (CVE-2026-48933) nodejs: Node.js: Certification validation bypass in TLS host verification (CVE-2026-48934) Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency (CVE-2026-48928) nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling (CVE-2026-48615) nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch (CVE-2026-48618) Bug Fix(es) and Enhancement(s): nodejs:22/nodejs: Rebase to the latest Node.js 22 release [rhel-8] (JIRA:RHEL-176170) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Solution For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Affected Products Red Hat Enterprise Linux for x86_64 8 x86_64 Red Hat Enterprise Linux for IBM z Systems 8 s390x Red Hat Enterprise Linux for Power, little endian 8 ppc64le Red Hat Enterprise Linux for ARM 64 8 aarch64 Red Hat Enterprise Linux for x86_64 - Extended Life Cycle 8.10 x86_64 Red Hat Enterprise Linux for ARM 64 - Extended Life Cycle 8.10 aarch64 Red Hat Enterprise Linux for Power, little endian - Extended Life Cycle 8.10 ppc64le Red Hat Enterprise Linux for IBM z Systems - Extended Life Cycle 8.10 s390x Fixes BZ - 2476810 - CVE-2026-42338 ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input BZ - 2489980 - CVE-2026-12151 undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames BZ - 2490000 - CVE-2026-9678 undici: Undici: Information disclosure due to improper cache-control header parsing BZ - 2490006 - CVE-2026-6733 undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. BZ - 2490008 - CVE-2026-11525 undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header BZ - 2493325 - CVE-2026-48619 nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames BZ - 2493326 - CVE-2026-48930 nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling BZ - 2493329 - CVE-2026-48935 nodejs: Node.js: Unauthorized file metadata modification BZ - 2493331 - CVE-2026-48933 nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() BZ - 2493332 - CVE-2026-48934 nodejs: Node.js: Certification validation bypass in TLS host verification BZ - 2493333 - CVE-2026-48928 Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency BZ - 2493335 - CVE-2026-48615 nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling BZ - 2493337 - CVE-2026-48618 nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch RHEL-176170 - nodejs:22/nodejs: Rebase to the latest Node.js 22 release [rhel-8] CVEs CVE-2026-6733 CVE-2026-9678 CVE-2026-11525 CVE-2026-12151 CVE-2026-42338 CVE-2026-48615 CVE-2026-48618 CVE-2026-48619 CVE-2026-48928 CVE-2026-48930 CVE-2026-48933 CVE-2026-48934 CVE-2026-48935 References https://access.redhat.com/security/updates/classification/#important Note: More recent versions of these packages may be available. Click a package name for more details. Red Hat Enterprise Linux for x86_64 8 SRPM nodejs-22.23.1-1.module+el8.10.0+24500+8eb51621.src.rpm SHA-256: eac2ff564a1dcfea74e6cd0c28e0611cfb54d919ac05a2b49013dd1b18113295 nodejs-nodemon-3.0.1-1.module+el8.10.0+24500+8eb51621.src.rpm SHA-256: c83bc48948952c8e0c9aa57315cedd8fefb59d9ad80238cd249938ab184be1ab nodejs-packaging-2021.06-6.module+el8.10.0+24500+8eb51621.src.rpm SHA-256: 1a7925e4c7910b86804252096b253ccc3c8d6095a08fd00b721fa03f98c6ab2c x86_64 nodejs-docs-22.23.1-1.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: 707ed604a3df4ae35e1f25ff99f04a2f260d80d2435a3513fddf5eda6f87b983 nodejs-nodemon-3.0.1-1.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: a1946ca2c19cc62cc1936ae1a7cd31ad185f417ad5a1b06c57f80a2b880ce3a2 nodejs-packaging-2021.06-6.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: bf54600cb7d5459379bf74a71b8e460762c0ae14cee429a7b146638620a8baf0 nodejs-packaging-bundler-2021.06-6.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: afd46d1b600dd9b55737e372aec93b388e9d6e30edaa887b3d4484333f33060f nodejs-22.23.1-1.module+el8.10.0+24500+8eb51621.x86_64.rpm SHA-256: 0f67e678823d6b09e2e3ff3478d0e722a5a52c57f7eba30980cd6bec941996b0 nodejs-debuginfo-22.23.1-1.module+el8.10.0+24500+8eb51621.x86_64.rpm SHA-256: e0ee7ad247cd67d0a02bd7abfc53c2b3fe108394c731f7fb03bfadaf556121a3 nodejs-debugsource-22.23.1-1.module+el8.10.0+24500+8eb51621.x86_64.rpm SHA-256: a8d844660b6becc3a71b5e0e1d421314ebafd5f58d46e4c869cdcbd4342a369d nodejs-devel-22.23.1-1.module+el8.10.0+24500+8eb51621.x86_64.rpm SHA-256: b8c95aa6acad5ffe5a463ab22ac6104f7012d7ad1f9edb8c3d24259c74e7304d nodejs-docs-22.23.1-1.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: 707ed604a3df4ae35e1f25ff99f04a2f260d80d2435a3513fddf5eda6f87b983 nodejs-full-i18n-22.23.1-1.module+el8.10.0+24500+8eb51621.x86_64.rpm SHA-256: 2fb4b5f83c2c8628df63d74f8cd4dcef66a879912ebf8145433cddc8e0d7781b nodejs-libs-22.23.1-1.module+el8.10.0+24500+8eb51621.x86_64.rpm SHA-256: 79979d874037708d4eecbb5d051858921a25007d1ffc48ae8315824a6cfc21dc nodejs-libs-debuginfo-22.23.1-1.module+el8.10.0+24500+8eb51621.x86_64.rpm SHA-256: ece5a3e8f129bc0a5b056cb336a7071017bc58558f93089d0e6b1612d8c0c51c nodejs-nodemon-3.0.1-1.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: a1946ca2c19cc62cc1936ae1a7cd31ad185f417ad5a1b06c57f80a2b880ce3a2 nodejs-packaging-2021.06-6.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: bf54600cb7d5459379bf74a71b8e460762c0ae14cee429a7b146638620a8baf0 nodejs-packaging-bundler-2021.06-6.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: afd46d1b600dd9b55737e372aec93b388e9d6e30edaa887b3d4484333f33060f npm-10.9.8-1.22.23.1.1.module+el8.10.0+24500+8eb51621.x86_64.rpm SHA-256: 9a7982d7fee1f0d79ee46e5ddd80272b7dede19ac0e58ab7c14eaf4ca7678120 v8-12.4-devel-12.4.254.21-1.22.23.1.1.module+el8.10.0+24500+8eb51621.x86_64.rpm SHA-256: 8fdc3519e1bc101d90481e9b9aebbff71d5ca1c0d38107c803519967f47bcd88 nodejs-docs-22.23.1-1.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: 707ed604a3df4ae35e1f25ff99f04a2f260d80d2435a3513fddf5eda6f87b983 nodejs-nodemon-3.0.1-1.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: a1946ca2c19cc62cc1936ae1a7cd31ad185f417ad5a1b06c57f80a2b880ce3a2 nodejs-packaging-2021.06-6.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: bf54600cb7d5459379bf74a71b8e460762c0ae14cee429a7b146638620a8baf0 nodejs-packaging-bundler-2021.06-6.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: afd46d1b600dd9b55737e372aec93b388e9d6e30edaa887b3d4484333f33060f nodejs-docs-22.23.1-1.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: 707ed604a3df4ae35e1f25ff99f04a2f260d80d2435a3513fddf5eda6f87b983 nodejs-nodemon-3.0.1-1.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: a1946ca2c19cc62cc1936ae1a7cd31ad185f417ad5a1b06c57f80a2b880ce3a2 nodejs-packaging-2021.06-6.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: bf54600cb7d5459379bf74a71b8e460762c0ae14cee429a7b146638620a8baf0 nodejs-packaging-bundler-2021.06-6.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: afd46d1b600dd9b55737e372aec93b388e9d6e30edaa887b3d4484333f33060f Red Hat Enterprise Linux for IBM z Systems 8 SRPM nodejs-22.23.1-1.module+el8.10.0+24500+8eb51621.src.rpm SHA-256: eac2ff564a1dcfea74e6cd0c28e0611cfb54d919ac05a2b49013dd1b18113295 nodejs-nodemon-3.0.1-1.module+el8.10.0+24500+8eb51621.src.rpm SHA-256: c83bc48948952c8e0c9aa57315cedd8fefb59d9ad80238cd249938ab184be1ab nodejs-packaging-2021.06-6.module+el8.10.0+24500+8eb51621.src.rpm SHA-256: 1a7925e4c7910b86804252096b253ccc3c8d6095a08fd00b721fa03f98c6ab2c s390x nodejs-docs-22.23.1-1.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: 707ed604a3df4ae35e1f25ff99f04a2f260d80d2435a3513fddf5eda6f87b983 nodejs-nodemon-3.0.1-1.module+el8.10.0+24500+8eb51621.noarch.rpm SHA-256: a1946ca2c19cc62cc1936ae1a7cd31ad185f417ad5a1b06c57f80a2b880ce3a2 nodejs-packaging-2021.06-6.module+el
This Red Hat Security Advisory addresses multiple vulnerabilities in the Node.js 22 module for RHEL 8, rated Important, including a high-severity denial of service in the `undici` library (CVE-2026-12151, CVSS 7.5) due to unbounded memory growth from WebSocket frames, and a medium-severity cross-site scripting flaw in the `ip-address` library (CVE-2026-42338, CVSS 6.1) via improper HTML escaping. The affected `undici` versions are 6.17.0 through 6.26.x, 7.0.0 through 7.27.x, and 8.0.0 through 8.4.x, which are fixed in versions 6.27.0, 7.28.0, and 8.5.0 respectively, while the `ip-address` library is fixed in version 10.1.1. The update also includes other security fixes, bug fixes, and enhancements, and administrators should apply the provided patches to their affected RHEL 8 systems.