RHSA-2026:41947HighCVSS 8.1

Red Hat Security Advisory: nodejs:22 security, bug fix, and enhancement update

Published
July 20, 2026
Last Modified
September 10, 2026

🔗 CVE IDs covered (13)

📋 Description

CVE-2026-6733 — undici: Undici: Response queue poisoning on reused keep-alive sockets can lead to incorrect response delivery. CVE-2026-9678 — undici: Undici: Information disclosure due to improper cache-control header parsing CVE-2026-11525 — undici: undici: Weakening of cookie SameSite policy due to incorrect parsing of Set-Cookie header CVE-2026-12151 — undici: undici: Denial of Service due to unbounded memory growth via WebSocket frames CVE-2026-42338 — ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input CVE-2026-48615 — nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling CVE-2026-48618 — nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch CVE-2026-48619 — nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames CVE-2026-48928 — Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency CVE-2026-48930 — nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling CVE-2026-48933 — nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() CVE-2026-48934 — nodejs: Node.js: Certification validation bypass in TLS host verification CVE-2026-48935 — nodejs: Node.js: Unauthorized file metadata modification

🎯 Affected products44

  • Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-1:22.23.1-1.module+el8.10.0+24500+8eb51621.aarch64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-1:22.23.1-1.module+el8.10.0+24500+8eb51621.ppc64le (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-1:22.23.1-1.module+el8.10.0+24500+8eb51621.s390x (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-1:22.23.1-1.module+el8.10.0+24500+8eb51621.src (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-1:22.23.1-1.module+el8.10.0+24500+8eb51621.x86_64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-debuginfo-1:22.23.1-1.module+el8.10.0+24500+8eb51621.aarch64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-debuginfo-1:22.23.1-1.module+el8.10.0+24500+8eb51621.ppc64le (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-debuginfo-1:22.23.1-1.module+el8.10.0+24500+8eb51621.s390x (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-debuginfo-1:22.23.1-1.module+el8.10.0+24500+8eb51621.x86_64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-debugsource-1:22.23.1-1.module+el8.10.0+24500+8eb51621.aarch64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-debugsource-1:22.23.1-1.module+el8.10.0+24500+8eb51621.ppc64le (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-debugsource-1:22.23.1-1.module+el8.10.0+24500+8eb51621.s390x (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-debugsource-1:22.23.1-1.module+el8.10.0+24500+8eb51621.x86_64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-devel-1:22.23.1-1.module+el8.10.0+24500+8eb51621.aarch64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-devel-1:22.23.1-1.module+el8.10.0+24500+8eb51621.ppc64le (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-devel-1:22.23.1-1.module+el8.10.0+24500+8eb51621.s390x (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-devel-1:22.23.1-1.module+el8.10.0+24500+8eb51621.x86_64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-docs-1:22.23.1-1.module+el8.10.0+24500+8eb51621.noarch (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-full-i18n-1:22.23.1-1.module+el8.10.0+24500+8eb51621.aarch64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-full-i18n-1:22.23.1-1.module+el8.10.0+24500+8eb51621.ppc64le (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-full-i18n-1:22.23.1-1.module+el8.10.0+24500+8eb51621.s390x (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-full-i18n-1:22.23.1-1.module+el8.10.0+24500+8eb51621.x86_64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-libs-1:22.23.1-1.module+el8.10.0+24500+8eb51621.aarch64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-libs-1:22.23.1-1.module+el8.10.0+24500+8eb51621.ppc64le (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-libs-1:22.23.1-1.module+el8.10.0+24500+8eb51621.s390x (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-libs-1:22.23.1-1.module+el8.10.0+24500+8eb51621.x86_64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-libs-debuginfo-1:22.23.1-1.module+el8.10.0+24500+8eb51621.aarch64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-libs-debuginfo-1:22.23.1-1.module+el8.10.0+24500+8eb51621.ppc64le (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • nodejs-libs-debuginfo-1:22.23.1-1.module+el8.10.0+24500+8eb51621.s390x (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 8)
  • +14 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

🔗 References (17)