[security - high] nodejs:22 security update
エラータID: AXSA:2026-1738:01
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
Security Fix(es):
* nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw (CVE-2026-58043)
* nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks (CVE-2026-56846)
* nodejs: Node.js: Heap-use-after-free in HTTP/2 handling can lead to denial of service (CVE-2026-56848)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-56846
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.
CVE-2026-56848
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
CVE-2026-58043
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
Modularity name: "nodejs"
Stream name: "22"
Update packages.
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
N/A
SRPMS
- nodejs-nodemon-3.1.14-2.module+el9+1192+6d0c5dab.src.rpm
MD5: 33012d008e2efd2e7c4aa843934f03c7
SHA-256: d660b5ccfa80e8b77a50ea34922a88e22a7c574ec079d71744215088cbbdcc81
Size: 455.16 kB - nodejs-packaging-2021.06-6.module+el9+1192+6d0c5dab.src.rpm
MD5: 703d97af5a17f4536259c5ab24e2d06f
SHA-256: c5a299bf89902fa89864179ab1d917d3273ebc58bd203eae3358bb6be596db32
Size: 25.41 kB - nodejs-22.23.2-1.module+el9+1192+6d0c5dab.src.rpm
MD5: 69e7a56f334e925d88d8d70f040c0382
SHA-256: 19eed3bd41f2e4d5ca402385384acbf492e16e712a727245506e133753e28677
Size: 92.46 MB
Asianux Server 9 for x86_64
- nodejs-22.23.2-1.module+el9+1192+6d0c5dab.x86_64.rpm
MD5: 79c31ae7e9878700ea93bf7570217671
SHA-256: a058d4bc9388d97ed02bdde8afe287672145a016e17d2c3d5aa89aaf0c096aec
Size: 2.18 MB - nodejs-debugsource-22.23.2-1.module+el9+1192+6d0c5dab.x86_64.rpm
MD5: 56cf4df105eb735e236b616141bedc2b
SHA-256: 2ab8ad0142c8f37e15fc58812e4437319e80304d73db4bbec16342be5de2f5a2
Size: 18.07 MB - nodejs-devel-22.23.2-1.module+el9+1192+6d0c5dab.x86_64.rpm
MD5: d7f773fc002c3129c09b26c82ae3cb61
SHA-256: 114ce417b353051393ec12667e7f504e445cadc9b9b695d69d92f306d82e3f87
Size: 277.45 kB - nodejs-docs-22.23.2-1.module+el9+1192+6d0c5dab.noarch.rpm
MD5: c17a110ea98928d5c27d89dba7ee562f
SHA-256: 0b2e63af2907a4c35b5accfb29f3df62d4f7cebd4dfdcbf75015333a6a4f05d7
Size: 9.25 MB - nodejs-full-i18n-22.23.2-1.module+el9+1192+6d0c5dab.x86_64.rpm
MD5: c51768d7d1e1b586622322a1a863115e
SHA-256: 8d3fc814bcbf2fd091eeb5ebbf59ec901c2a8f2713bc57ac76deb66ace40f87e
Size: 8.87 MB - nodejs-libs-22.23.2-1.module+el9+1192+6d0c5dab.x86_64.rpm
MD5: 6be3d518b70355fe09fe345c1c70522a
SHA-256: 1c4ea6e55717c3083a421c18e762daed132da12cf71e680b92f6cc5c1d1eca23
Size: 20.55 MB - nodejs-nodemon-3.1.14-2.module+el9+1192+6d0c5dab.noarch.rpm
MD5: 47fa167ae8de86c58c89370c2a5f92ec
SHA-256: f024f2f61641962d7b8990ad3702dd19577b60c19e6072759e1ac62f2770b998
Size: 373.91 kB - nodejs-packaging-2021.06-6.module+el9+1192+6d0c5dab.noarch.rpm
MD5: 59a4f68b773d7c8bd46dfdb21ea36ff3
SHA-256: 7311524fc16d4233f94fc91090180085b046656b5e03d639e64285ddce903edc
Size: 18.66 kB - nodejs-packaging-bundler-2021.06-6.module+el9+1192+6d0c5dab.noarch.rpm
MD5: 604e3d7de6d51102f067539718741552
SHA-256: e050004990cf5b2a4af4663d969a1124380aedcf70b27d5b392d071db42d57e5
Size: 8.47 kB - npm-10.9.8-1.22.23.2.1.module+el9+1192+6d0c5dab.x86_64.rpm
MD5: 1aec07ebcdcff045a8ead068ea4a2d44
SHA-256: 4edc073a486b2fa1e5e0357caf5bd992454f0c8e5b26223dcf7dbc35084601d5
Size: 2.37 MB - v8-12.4-devel-12.4.254.21-1.22.23.2.1.module+el9+1192+6d0c5dab.x86_64.rpm
MD5: 6fa5a67c58783524f71afd802a283bb0
SHA-256: acc896f52c4471b471a3c8ae0c1760e9833ab300e7073ae42475f8daf4da2b5f
Size: 16.40 kB