[security - high] nodejs:24 security update
エラータID: AXSA:2026-1455:01
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
Security Fix(es):
* brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
* tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
* tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-13149
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
CVE-2026-59873
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
CVE-2026-59874
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
Modularity name: "nodejs"
Stream name: "24"
Update packages.
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
N/A
SRPMS
- nodejs-nodemon-3.1.14-1.module+el8+2018+41e4b584.src.rpm
MD5: 4d5142691dfcff1d88bdc4a1a334f115
SHA-256: dafed16a79ff8a8cac1a132afce6cc5074f8de1f7d68bd6b306be0eba8c401dd
Size: 453.15 kB - nodejs-packaging-2021.06-6.module+el8+2018+41e4b584.src.rpm
MD5: ed22d9e3bbd818ffd3f94b49c1fd8560
SHA-256: 748d94f7af576d14a8ab6347f17540a3f3e4a633c70ccf5fe80cdae9acc43610
Size: 30.67 kB - nodejs-24.18.0-2.module+el8+2018+41e4b584.src.rpm
MD5: 5bf3a58995c0254766c100512b93c17c
SHA-256: 100b8afb309ded3f9a72ddd6020032b20692e35b7e981f125dd32fe470fd45de
Size: 98.86 MB
Asianux Server 8 for x86_64
- nodejs-24.18.0-2.module+el8+2018+41e4b584.x86_64.rpm
MD5: df02a32a9a71703713596beb17d6bb21
SHA-256: 6d80a945f19f79ea8b13985aff4a955d49bc96d5d60f688d5bcae3d8a6c8ecfc
Size: 67.72 kB - nodejs-debugsource-24.18.0-2.module+el8+2018+41e4b584.x86_64.rpm
MD5: 225f58be4c29771c0de566aa4c339698
SHA-256: 9615931748e6851c68e70e9f71d4e48e69905f2c8befdd368bce2e13e4446dc4
Size: 21.48 MB - nodejs-devel-24.18.0-2.module+el8+2018+41e4b584.x86_64.rpm
MD5: 3c6136e2ac9dc0b5451ebc0c3fabbdcd
SHA-256: fe84dcd2b47a1f36054605185972e58ca4aaf04a894f4c489fca35da1fbb85a8
Size: 330.44 kB - nodejs-docs-24.18.0-2.module+el8+2018+41e4b584.noarch.rpm
MD5: 2d9503fb8a3887eb2a6c7ebf7fd3fb94
SHA-256: cf78a453edc3017c1afedf8d0a3a2d81a62170368ae4606f5198f509ddd219c9
Size: 6.28 MB - nodejs-full-i18n-24.18.0-2.module+el8+2018+41e4b584.x86_64.rpm
MD5: 20156e2b23396e908758ffc540b5adc7
SHA-256: 752feea3a2a32fe6f7c9d4fcfe31af07a41397d0479db56c39b6fe3b3ee51f01
Size: 8.61 MB - nodejs-libs-24.18.0-2.module+el8+2018+41e4b584.x86_64.rpm
MD5: e98c3e974bff2fc0b0f5c3951d3c16b6
SHA-256: f9d6d8bc33d7f0cde02d62c7e41cf435aa401893106e274231d6e1c2c283e56c
Size: 18.83 MB - nodejs-nodemon-3.1.14-1.module+el8+2018+41e4b584.noarch.rpm
MD5: 704f7983a6165b8f2d798fc3961ffb8a
SHA-256: 5e5216086c8f63f3504b0ac7622afffd652e550179dac4764008e0d22da56e3c
Size: 318.92 kB - nodejs-packaging-2021.06-6.module+el8+2018+41e4b584.noarch.rpm
MD5: 6c4d7c9abe46962aca21b2b301f645e5
SHA-256: 54bc84cb0e532ecf88cbf4293e8b2dee99b3fedadadb3cbaa3cdf0aa3fbb0069
Size: 24.41 kB - nodejs-packaging-bundler-2021.06-6.module+el8+2018+41e4b584.noarch.rpm
MD5: 8f78df3154c2576ce1b212548ec98ed9
SHA-256: 0daa2023f54678eb83e43863111be665d521fd987075ac115e7e44c7b6494c81
Size: 13.99 kB - npm-11.16.0-1.24.18.0.2.module+el8+2018+41e4b584.noarch.rpm
MD5: fde1ed563d5a657724ce47c66c56c940
SHA-256: 1a212aa24ca82b81ed06960e4600a5f5573f20f4bb241365e721f74ee03d9e3c
Size: 2.30 MB - v8-13.6-devel-13.6.233.17-1.24.18.0.2.module+el8+2018+41e4b584.x86_64.rpm
MD5: ff407e4ec6148d5513b4e5f351f01969
SHA-256: ba24a7270c671fbb4ab55b1b8005e5b8eb1284e221bcb72a5c402a4dc7bbf99c
Size: 33.30 kB