VYPR

rpm package

almalinux/nodejs24-docs

pkg:rpm/almalinux/nodejs24-docs

Vulnerabilities (48)

  • CVE-2026-56848HigAug 4, 2026
    affected < 1:24.19.0-1.el10_2fixed 1:24.19.0-1.el10_2

    A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

  • CVE-2026-56846HigAug 4, 2026
    affected < 1:24.19.0-1.el10_2fixed 1:24.19.0-1.el10_2

    A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.

  • CVE-2026-69192HigAug 3, 2026
    affected < 1:24.18.0-5.el10_2fixed 1:24.18.0-5.el10_2

    ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a leading zero and decodes it as decimal, while the WHATWG URL host parser, inet_aton, and getaddrinfo all decode a leading zero as

  • CVE-2026-69152HigAug 3, 2026
    affected < 1:24.18.0-5.el10_2fixed 1:24.18.0-5.el10_2

    The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() does not apply maxLength while constructing comma-alternative intermediate arrays or padded sequences, allowing attacker-controlled in

  • CVE-2026-58043HigJul 30, 2026
    affected < 1:24.19.0-1.el10_2fixed 1:24.19.0-1.el10_2

    A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem a

  • CVE-2026-54272MedJul 27, 2026
    affected < 1:24.18.0-5.el10_2fixed 1:24.18.0-5.el10_2

    ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF through misclassification of IPv4-mapped/NAT64 IPv6 addresses. Address6.getType() classifies an address by matching it against a table

  • CVE-2026-14257HigJul 23, 2026
    affected < 1:24.18.0-5.el10_2fixed 1:24.18.0-5.el10_2

    brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion. The expand() function limits the number of results with a max option (default 100,000) but does not bound the length of each result string. By chaining multiple brace groups, an attacker keeps

  • CVE-2026-59874HigJul 8, 2026
    affected < 1:24.18.0-3.el10_2fixed 1:24.18.0-3.el10_2

    node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed

  • CVE-2026-59873HigJul 8, 2026
    affected < 1:24.18.0-3.el10_2fixed 1:24.18.0-3.el10_2

    node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to

  • CVE-2026-13149HigJun 30, 2026
    affected < 1:24.18.0-3.el10_2fixed 1:24.18.0-3.el10_2

    brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause sign

  • CVE-2026-48935LowJun 26, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

  • CVE-2026-48934MedJun 26, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

  • CVE-2026-48933HigJun 26, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

  • CVE-2026-48930CriJun 26, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

  • CVE-2026-48928MedJun 26, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

  • CVE-2026-48619HigJun 26, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.

  • CVE-2026-48618MedJun 26, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security

  • CVE-2026-48615HigJun 26, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers

  • CVE-2026-9697HigJun 17, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthor

  • CVE-2026-9678MedJun 17, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=" authorization" or no-cache="\tauthorization". The parser preserves the s

Page 1 of 3