RHSA-2026:7896HighCVSS 7.5

Red Hat Security Advisory: nodejs:20 security update

Published
April 13, 2026
Last Modified
May 26, 2026

🔗 CVE IDs covered (4)

CVE-2026-26996 · pendingCVE-2026-27135CVE-2026-27904 · pendingCVE-2026-21710 · pending

📋 Description

CVE-2026-21710 — Node.js: Node.js: Denial of Service due to crafted HTTP __proto__ header CVE-2026-26996 — minimatch: minimatch: Denial of Service via specially crafted glob patterns CVE-2026-27135 — nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination CVE-2026-27904 — minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions

🔗 References (8)