rpm package
almalinux/nodejs24-docs
pkg:rpm/almalinux/nodejs24-docs
Vulnerabilities (48)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-56848 | Hig | 7.5 | < 1:24.19.0-1.el10_2 | 1:24.19.0-1.el10_2 | Aug 4, 2026 | A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**. | |
| CVE-2026-56846 | Hig | 7.5 | < 1:24.19.0-1.el10_2 | 1:24.19.0-1.el10_2 | Aug 4, 2026 | A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**. | |
| CVE-2026-69192 | Hig | — | < 1:24.18.0-5.el10_2 | 1:24.18.0-5.el10_2 | Aug 3, 2026 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as | |
| CVE-2026-69152 | Hig | 7.5 | < 1:24.18.0-5.el10_2 | 1:24.18.0-5.el10_2 | Aug 3, 2026 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled in | |
| CVE-2026-58043 | Hig | 8.4 | < 1:24.19.0-1.el10_2 | 1:24.19.0-1.el10_2 | Jul 30, 2026 | A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem a | |
| CVE-2026-54272 | Med | — | < 1:24.18.0-5.el10_2 | 1:24.18.0-5.el10_2 | Jul 27, 2026 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifies an address by matching it against a table | |
| CVE-2026-14257 | Hig | 7.5 | < 1:24.18.0-5.el10_2 | 1:24.18.0-5.el10_2 | Jul 23, 2026 | brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps | |
| CVE-2026-59874 | Hig | 7.5 | < 1:24.18.0-3.el10_2 | 1:24.18.0-3.el10_2 | Jul 8, 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed | |
| CVE-2026-59873 | Hig | 7.5 | < 1:24.18.0-3.el10_2 | 1:24.18.0-3.el10_2 | Jul 8, 2026 | node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to | |
| CVE-2026-13149 | Hig | — | < 1:24.18.0-3.el10_2 | 1:24.18.0-3.el10_2 | Jun 30, 2026 | brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause sign | |
| CVE-2026-48935 | Low | 3.3 | < 1:24.18.0-1.el10_2 | 1:24.18.0-1.el10_2 | Jun 26, 2026 | A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| CVE-2026-48934 | Med | 4.3 | < 1:24.18.0-1.el10_2 | 1:24.18.0-1.el10_2 | Jun 26, 2026 | A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| CVE-2026-48933 | Hig | 7.5 | < 1:24.18.0-1.el10_2 | 1:24.18.0-1.el10_2 | Jun 26, 2026 | A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| CVE-2026-48930 | Cri | 9.8 | < 1:24.18.0-1.el10_2 | 1:24.18.0-1.el10_2 | Jun 26, 2026 | A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| CVE-2026-48928 | Med | 5.4 | < 1:24.18.0-1.el10_2 | 1:24.18.0-1.el10_2 | Jun 26, 2026 | A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| CVE-2026-48619 | Hig | 7.5 | < 1:24.18.0-1.el10_2 | 1:24.18.0-1.el10_2 | Jun 26, 2026 | A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | |
| CVE-2026-48618 | Med | 6.5 | < 1:24.18.0-1.el10_2 | 1:24.18.0-1.el10_2 | Jun 26, 2026 | A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security | |
| CVE-2026-48615 | Hig | 7.5 | < 1:24.18.0-1.el10_2 | 1:24.18.0-1.el10_2 | Jun 26, 2026 | A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers | |
| CVE-2026-9697 | Hig | 7.4 | < 1:24.18.0-1.el10_2 | 1:24.18.0-1.el10_2 | Jun 17, 2026 | Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthor | |
| CVE-2026-9678 | Med | 5.9 | < 1:24.18.0-1.el10_2 | 1:24.18.0-1.el10_2 | Jun 17, 2026 | Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=" authorization" or no-cache="\tauthorization". The parser preserves the s |
- affected < 1:24.19.0-1.el10_2fixed 1:24.19.0-1.el10_2
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
- affected < 1:24.19.0-1.el10_2fixed 1:24.19.0-1.el10_2
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.
- affected < 1:24.18.0-5.el10_2fixed 1:24.18.0-5.el10_2
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as
- affected < 1:24.18.0-5.el10_2fixed 1:24.18.0-5.el10_2
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled in
- affected < 1:24.19.0-1.el10_2fixed 1:24.19.0-1.el10_2
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem a
- affected < 1:24.18.0-5.el10_2fixed 1:24.18.0-5.el10_2
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifies an address by matching it against a table
- affected < 1:24.18.0-5.el10_2fixed 1:24.18.0-5.el10_2
brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps
- affected < 1:24.18.0-3.el10_2fixed 1:24.18.0-3.el10_2
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed
- affected < 1:24.18.0-3.el10_2fixed 1:24.18.0-3.el10_2
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to
- affected < 1:24.18.0-3.el10_2fixed 1:24.18.0-3.el10_2
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause sign
- affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2
A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
- affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2
A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
- affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2
A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
- affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
- affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2
A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
- affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2
A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
- affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2
A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security
- affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2
A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers
- affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2
Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthor
- affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2
Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=" authorization" or no-cache="\tauthorization". The parser preserves the s
Page 1 of 3