RHSA-2026:61383HighCVSS 7.5

Red Hat Security Advisory: nodejs:22 security update

Published
August 31, 2026
Last Modified
August 31, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2026-56846 — nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks CVE-2026-56848 — nodejs: Node.js: Heap-use-after-free in HTTP/2 handling can lead to denial of service CVE-2026-58043 — nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw

🎯 Affected products44

  • Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.aarch64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.ppc64le (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.s390x (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.src (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.x86_64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-debuginfo-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.aarch64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-debuginfo-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.ppc64le (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-debuginfo-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.s390x (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-debuginfo-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.x86_64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-debugsource-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.aarch64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-debugsource-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.ppc64le (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-debugsource-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.s390x (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-debugsource-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.x86_64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-devel-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.aarch64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-devel-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.ppc64le (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-devel-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.s390x (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-devel-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.x86_64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-docs-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.noarch (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-full-i18n-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.aarch64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-full-i18n-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.ppc64le (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-full-i18n-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.s390x (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-full-i18n-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.x86_64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-libs-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.aarch64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-libs-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.ppc64le (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-libs-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.s390x (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-libs-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.x86_64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-libs-debuginfo-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.aarch64 (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-libs-debuginfo-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.ppc64le (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • nodejs-libs-debuginfo-1:22.23.2-1.module+el9.8.0+24709+804d6b5b.s390x (nodejs:22) as a component of Red Hat Enterprise Linux AppStream (v. 9)
  • +14 more not shown

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 Workaround: To mitigate this issue, restrict network access to Node.js applications utilizing HTTP/2 to trusted clients only, by implementing firewall rules or network access controls. If HTTP/2 functionality is not essential for the application, consider disabling it in the Node.js configuration to prevent exploitation. Always ensure that any service restarts or reloads are performed carefully to avoid service disruption. Workaround: Restrict network access to Node.js HTTP/2 listeners to trusted clients only. If HTTP/2 is not required, disable it to remove the vulnerable handler from the attack surface. Workaround: Avoid enabling the Node.js Permission Model by not using the `--permission` flag when starting Node.js applications. This prevents the vulnerable enforcement mechanism from being active. Disabling the Permission Model may remove an intended security layer if your application relies on it for sandboxing.

🔗 References (5)