RHSA-2026:7378HighCVSS 7.7

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Published
April 10, 2026
Last Modified
July 31, 2026

🔗 CVE IDs covered (21)

📋 Description

CVE-2025-55130 — nodejs: Nodejs file permissions bypass CVE-2025-55131 — nodejs: Nodejs uninitialized memory exposure CVE-2025-55132 — nodejs: Nodejs filesystem permissions bypass CVE-2025-59464 — nodejs: Nodejs memory leak CVE-2026-2950 — lodash: Lodash: Prototype pollution allows deletion of built-in prototype properties via array path bypass CVE-2026-6734 — undici: undici: Information disclosure and data integrity issues due to incorrect Socks5ProxyAgent connection routing CVE-2026-9675 — undici: undici WebSocket client vulnerable to denial of service via cumulative fragment bypass CVE-2026-9678 — undici: Undici: Information disclosure due to improper cache-control header parsing CVE-2026-9697 — undici: undici: Man-in-the-Middle attack via ignored TLS options with SOCKS5 proxy CVE-2026-45149 — brace-expansion: brace-expansion: Denial of Service due to excessive memory allocation when expanding large numeric ranges CVE-2026-48615 — nodejs: Node.js: Information disclosure of proxy credentials via proxy tunnel error handling CVE-2026-48618 — nodejs: Node.js: Authentication bypass due to TLS hostname handling and unicode dot separator mismatch CVE-2026-48619 — nodejs: Node.js: Denial of Service via unlimited HTTP/2 ORIGIN frames CVE-2026-48928 — Node.js: Node.js: Trust-policy bypass due to hostname matching inconsistency CVE-2026-48930 — nodejs: Node.js: Silent authority rebinding due to embedded-nul hostnames in TLS handling CVE-2026-48933 — nodejs: Node.js WebCrypto: Denial of Service via large input to subtle.encrypt() CVE-2026-48934 — nodejs: Node.js: Certification validation bypass in TLS host verification CVE-2026-48935 — nodejs: Node.js: Unauthorized file metadata modification CVE-2026-48936 — nodejs: Node.js: Local server can be started without network permission via Permission API flaw CVE-2026-59868 — js-yaml: js-yaml: Denial of Service via quadratic CPU time parsing with merge keys CVE-2026-59870 — js-yaml: js-yaml: Denial of Service via crafted YAML ordered-map document

🎯 Affected products5

  • Red Hat Hardened Images
  • nodejs25-main@aarch64 as a component of Red Hat Hardened Images
  • nodejs25-main@noarch as a component of Red Hat Hardened Images
  • nodejs25-main@src as a component of Red Hat Hardened Images
  • nodejs25-main@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability. Workaround: The single most impactful mitigation is applying network egress controls to restrict which external destinations affected applications can reach. Because the vulnerability causes requests to be misrouted to wrong origins, limiting the set of reachable origins directly reduces the attack surface. These controls collectively limit the blast radius of the connection pool misrouting — the attacker must compromise one of the explicitly allowed destinations rather than any arbitrary origin — but they do not fix the underlying logic bug. Workaround: Red Hat products that bundle the undici HTTP client ship versions 5.x, 6.x, and 7.x, which do not contain the vulnerable WebSocket frame accumulation code path introduced in undici 8.0.0. No Red Hat product streams are affected by this vulnerability. Users who have manually installed undici 8.x outside of Red Hat-provided packages should upgrade to undici 8.5.0 or later to fully resolve this issue. Workaround: Upgrade to js-yaml 5.2.0 or later. Where an immediate upgrade is not possible, avoid parsing untrusted YAML documents that use merge keys ('<<'), or apply size and time limits when parsing untrusted YAML input. Workaround: Avoid using the YAML11_SCHEMA when parsing untrusted YAML input, or upgrade to js-yaml 5.2.1 or later. Applications using the default schema (CORE_SCHEMA) are not affected.

🔗 References (25)