Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
🔗 CVE IDs covered (10)
📋 Description
CVE-2026-13697 — undici: undici: Information disclosure and Denial of Service via malformed Cache-Control directives CVE-2026-14643 — undici: undici: Cross-user information disclosure due to improper Cache-Control directive parsing CVE-2026-15157 — undici: undici: HTTP header injection via unvalidated blob-like body type property CVE-2026-16728 — undici: undici: Response desynchronization via retry interceptor with mismatched Content-Length CVE-2026-16729 — undici: Undici: Cookie attribute injection allows bypassing security protections CVE-2026-56847 — nodejs: Node.js: Permission Model flaw allows trace logs to bypass filesystem write restrictions CVE-2026-56850 — nodejs: Node.js: mTLS client identities can be reused due to HTTPS Agent connection flaw CVE-2026-58039 — nodejs: Information disclosure due to improper permission enforcement CVE-2026-58040 — nodejs: HTTPS Agent TLS session reuse skips hostname verification CVE-2026-58043 — nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw
🎯 Affected products5
- Red Hat Hardened Images
- nodejs26-main@aarch64 as a component of Red Hat Hardened Images
- nodejs26-main@noarch as a component of Red Hat Hardened Images
- nodejs26-main@src as a component of Red Hat Hardened Images
- nodejs26-main@x86_64 as a component of Red Hat Hardened Images
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Avoid using the trace_events.createTracing().enable() function in environments that rely on the Node.js Permission Model for file system isolation. Be aware that avoiding this function disables dynamic trace log generation, which may impact performance profiling, APM monitoring, and diagnostic workflows. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: To mitigate this issue, avoid enabling the experimental Node.js Permission Model by not using the `--experimental-permission` flag. Additionally, ensure that untrusted Node.js workloads are executed within robust operating system isolation primitives, such as Linux containers or cgroups, to limit potential impact. Workaround: To mitigate this issue, Node.js applications should be designed to explicitly configure unique HTTPS agents for each distinct target host. Alternatively, applications can avoid TLS session caching when making outbound HTTPS requests to varied third-party endpoints using shared client instances. Implementing these application-level changes will prevent the vulnerable behavior of skipping hostname verification. Applications may require a restart to apply these changes. Workaround: Avoid enabling the Node.js Permission Model by not using the `--permission` flag when starting Node.js applications. This prevents the vulnerable enforcement mechanism from being active. Disabling the Permission Model may remove an intended security layer if your application relies on it for sandboxing.
🔗 References (14)
- selfhttps://access.redhat.com/errata/RHSA-2026:48273
- externalhttps://images.redhat.com/
- externalhttps://access.redhat.com/security/cve/CVE-2026-58043
- externalhttps://access.redhat.com/security/updates/classification/
- externalhttps://access.redhat.com/security/cve/CVE-2026-56847
- externalhttps://access.redhat.com/security/cve/CVE-2026-56850
- externalhttps://access.redhat.com/security/cve/CVE-2026-58040
- externalhttps://access.redhat.com/security/cve/CVE-2026-15157
- externalhttps://access.redhat.com/security/cve/CVE-2026-14643
- externalhttps://access.redhat.com/security/cve/CVE-2026-16728
- externalhttps://access.redhat.com/security/cve/CVE-2026-16729
- externalhttps://access.redhat.com/security/cve/CVE-2026-13697
- externalhttps://access.redhat.com/security/cve/CVE-2026-58039
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_48273.json