[security - high] nodejs:22 security update
エラータID: AXSA:2026-1561:01
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
Security Fix(es):
* brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
* tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
* tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-13149
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
CVE-2026-59873
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
CVE-2026-59874
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
Modularity name: "nodejs"
Stream name: "22"
Update packages.
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
N/A
SRPMS
- nodejs-nodemon-3.1.14-1.module+el9+1182+1ddc658b.src.rpm
MD5: 8f23aa845903a9889941458b4dd8efe4
SHA-256: b6f1b83d14dafe28d3a0a6e118e1fcb9073fb005893faff911e4801aebde6a94
Size: 455.15 kB - nodejs-packaging-2021.06-6.module+el9+1182+1ddc658b.src.rpm
MD5: 4f944f4b5c1ce57fa1b75eddda3f48dc
SHA-256: 7a1cf393f581b44e252ed3c68d8252bff346caed523a7c51764b0b25c3e4ba34
Size: 25.41 kB - nodejs-22.23.1-2.module+el9+1182+1ddc658b.src.rpm
MD5: 3ecd329bd6d9aec730c79e82001c1ddb
SHA-256: ff6f5ea961f3c3a97d18dc971a6039c61ed77a09fea9cfa2bd2314d2c5ffcdfb
Size: 92.22 MB
Asianux Server 9 for x86_64
- nodejs-22.23.1-2.module+el9+1182+1ddc658b.x86_64.rpm
MD5: 1d3608ee06c12aa5bf0b6191e0bd8c7a
SHA-256: 52fa46d2906ae25bb88b014aac44d51e9333a3eef9e2889160c3518a28b9fdef
Size: 2.18 MB - nodejs-debugsource-22.23.1-2.module+el9+1182+1ddc658b.x86_64.rpm
MD5: 2ac6bad3d740974ae661a9587b49ce8f
SHA-256: c7b4c7d2af0cd650c3bfc4bccb411ca2b252821f8b1e7793bb1abf332439e5ae
Size: 18.05 MB - nodejs-devel-22.23.1-2.module+el9+1182+1ddc658b.x86_64.rpm
MD5: acfdad58651d41aa84046c9c132d02cc
SHA-256: 759a44c0da31d1cdcd30e7ee4460740b889d3ee756bca1359f5f9602ee363b9b
Size: 276.89 kB - nodejs-docs-22.23.1-2.module+el9+1182+1ddc658b.noarch.rpm
MD5: 5cd4199ebd5ce8234bc98e9dd71c5a3c
SHA-256: 2ae34ca2d40cc4a71a64b3d9e86005bca121cc79075563aaec69764639d142ff
Size: 9.24 MB - nodejs-full-i18n-22.23.1-2.module+el9+1182+1ddc658b.x86_64.rpm
MD5: 834164601dc30c804698315567a0db0b
SHA-256: c80417c5caa6912cbe93f14fd5b26c129835794597da93ddcc36ece50aba6650
Size: 8.87 MB - nodejs-libs-22.23.1-2.module+el9+1182+1ddc658b.x86_64.rpm
MD5: e1b56b3cc4e21ddaaf346baab939f8f6
SHA-256: 21bb23a2aef0a3cdb30f5e00b86d0bf75aa32ae735c9a89900e955b0a098b6c5
Size: 20.54 MB - nodejs-nodemon-3.1.14-1.module+el9+1182+1ddc658b.noarch.rpm
MD5: a06bd96276e1dd11a3eee82e5cf1ec13
SHA-256: d518bb2cfdfddf9d8e7be05730fb05952cfab75977096a0f7f79f3020728f338
Size: 373.84 kB - nodejs-packaging-2021.06-6.module+el9+1182+1ddc658b.noarch.rpm
MD5: d02afac7f478004eb332339d4c138d3d
SHA-256: c19dea017e21c73229f4be5102471c76bc9b4e96b5cb0d254434ebad204531a4
Size: 18.66 kB - nodejs-packaging-bundler-2021.06-6.module+el9+1182+1ddc658b.noarch.rpm
MD5: 0f634fa1244b1586dbc99f36f33cb564
SHA-256: 010c07d5c71dba60957aad5d375c0c1eec1ac7fc805440c8c110e9c8b6558f1c
Size: 8.47 kB - npm-10.9.8-1.22.23.1.2.module+el9+1182+1ddc658b.x86_64.rpm
MD5: 232cc363f4fe89c5e0c680c05d0ba813
SHA-256: e1306bafc676053bfc8d54d5d6867b6f6879abcb033c905f5b07b36a30aab4ad
Size: 2.36 MB - v8-12.4-devel-12.4.254.21-1.22.23.1.2.module+el9+1182+1ddc658b.x86_64.rpm
MD5: 2b4de61bc4ec0f184d867a91cb8aa373
SHA-256: 9175549fe60f841c2aa1a3a3bbf5e6be1ac841fd59e83f183e4a01ec22b8f980
Size: 15.87 kB