Red Hat Security Advisory: nodejs22 security update
🔗 CVE IDs covered (3)
📋 Description
CVE-2026-14257 — brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function CVE-2026-69152 — brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation CVE-2026-69192 — ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass
🎯 Affected products39
- Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-1:22.23.1-6.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-1:22.23.1-6.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-1:22.23.1-6.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-1:22.23.1-6.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-debuginfo-1:22.23.1-6.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-debuginfo-1:22.23.1-6.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-debuginfo-1:22.23.1-6.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-debuginfo-1:22.23.1-6.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-devel-1:22.23.1-6.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-devel-1:22.23.1-6.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-devel-1:22.23.1-6.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-devel-1:22.23.1-6.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-docs-1:22.23.1-6.el10_2.noarch as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-full-i18n-1:22.23.1-6.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-full-i18n-1:22.23.1-6.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-full-i18n-1:22.23.1-6.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-full-i18n-1:22.23.1-6.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-libs-1:22.23.1-6.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-libs-1:22.23.1-6.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-libs-1:22.23.1-6.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-libs-1:22.23.1-6.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-libs-debuginfo-1:22.23.1-6.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-libs-debuginfo-1:22.23.1-6.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-libs-debuginfo-1:22.23.1-6.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-libs-debuginfo-1:22.23.1-6.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-npm-1:10.9.8-1.22.23.1.6.el10_2.aarch64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-npm-1:10.9.8-1.22.23.1.6.el10_2.ppc64le as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-npm-1:10.9.8-1.22.23.1.6.el10_2.s390x as a component of Red Hat Enterprise Linux AppStream (v. 10)
- nodejs-npm-1:10.9.8-1.22.23.1.6.el10_2.x86_64 as a component of Red Hat Enterprise Linux AppStream (v. 10)
- +9 more not shown
✅ Remediation
For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: Do not pass untrusted or user-controlled input to brace-expansion's expand() function or to libraries that use it for glob pattern matching (such as minimatch or glob). Validate and sanitize any brace patterns before expansion. Where possible, upgrade to brace-expansion 1.1.17, 2.1.3, 3.0.3, or 5.0.8 which add a maxLength option that bounds accumulated output. As an additional defense-in-depth measure, enforce memory limits on Node.js processes using operating system resource controls such as cgroups or Kubernetes resource limits (spec.containers[].resources.limits.memory) to prevent a single process from exhausting system memory and causing a wider outage. Workaround: To mitigate this vulnerability, do not pass untrusted input to the expand() function. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
🔗 References (6)
- selfhttps://access.redhat.com/errata/RHSA-2026:55541
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2506433
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510722
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2510801
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_55541.json