[security - high] nodejs:24 security update
エラータID: AXSA:2026-1739:01
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
Security Fix(es):
* nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw (CVE-2026-58043)
* nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks (CVE-2026-56846)
* nodejs: Node.js: Heap-use-after-free in HTTP/2 handling can lead to denial of service (CVE-2026-56848)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-56846
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.
CVE-2026-56848
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
CVE-2026-58043
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
Modularity name: "nodejs"
Stream name: "24"
Update packages.
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
N/A
SRPMS
- nodejs-nodemon-3.1.14-3.module+el9+1191+8414e80b.src.rpm
MD5: 799361e4aadd7f1982f077ca2b0efb9f
SHA-256: ed1f42d57af7e79c84a8ff631c7388139d57e529703734bb43bd8718ffe5ab08
Size: 462.94 kB - nodejs-packaging-2021.06-6.module+el9+1191+8414e80b.src.rpm
MD5: 1debefb7443d77cc7478be73cd037a0b
SHA-256: cc88e36f212e6c21c2d98c1bc94123df1d3aabb4f413a683e1cca964d496fc26
Size: 25.41 kB - nodejs-24.19.0-1.module+el9+1191+8414e80b.src.rpm
MD5: a812302ef3f4cf2398312c8b3076245c
SHA-256: 1d7d92d165dbb0327e66ffd2486aba2f00341e001609170dc508862e03e44537
Size: 98.64 MB
Asianux Server 9 for x86_64
- nodejs-24.19.0-1.module+el9+1191+8414e80b.x86_64.rpm
MD5: 19d6dee74c3aba1ef0df46a55cbcbfaf
SHA-256: 6a277e464c47cfd64e7cebf99f909955ff7acd0a28dd144c1fe787cdde47c805
Size: 68.73 kB - nodejs-debugsource-24.19.0-1.module+el9+1191+8414e80b.x86_64.rpm
MD5: ddd35f1a2f079b85b470f0b5a97a7a02
SHA-256: 6c93e08c18d0aabf1b28741d877306eb356aa66a3cede39ebbf1af64a9e3d6f9
Size: 21.03 MB - nodejs-devel-24.19.0-1.module+el9+1191+8414e80b.x86_64.rpm
MD5: 4b82f39dbe8afacd5bf98705775189ed
SHA-256: ea0efef659b8fe3e2b393f4112c77b5c93aa70d1414c49efaea1f16a026b45bb
Size: 335.91 kB - nodejs-docs-24.19.0-1.module+el9+1191+8414e80b.noarch.rpm
MD5: 32eeafbcb7deef8a39561c30790f99d5
SHA-256: 2a049b761270e63e42e4777e548186cdf11827a609ca50a96732b252ca447c82
Size: 5.13 MB - nodejs-full-i18n-24.19.0-1.module+el9+1191+8414e80b.x86_64.rpm
MD5: f7b4021960c5acbff0272faf4ddfac9e
SHA-256: 9e548f7f77df80d3c09b54fd291a310860b3665600694215251fc3756d2af887
Size: 8.87 MB - nodejs-libs-24.19.0-1.module+el9+1191+8414e80b.x86_64.rpm
MD5: 8b9941650a7eeb108efd7c6a527d1b61
SHA-256: 73baf697a5f70f49fe281f2df05b8490082355400c156e8bb326442a7cea82b7
Size: 23.54 MB - nodejs-nodemon-3.1.14-3.module+el9+1191+8414e80b.noarch.rpm
MD5: ed1fb0c07e9c59ec2fd92d0117fb6637
SHA-256: 6ecc82eecfc3cb0994a118fbdec2035b939bd888485e99c45f9fa194b687afb4
Size: 376.18 kB - nodejs-packaging-2021.06-6.module+el9+1191+8414e80b.noarch.rpm
MD5: 415f55cf66bd6168f2c48615fb9b988f
SHA-256: 75d0ce06b906315a1b7ea8332c8019e6cfb5f65d5b64b9ae5157195361a0c069
Size: 18.66 kB - nodejs-packaging-bundler-2021.06-6.module+el9+1191+8414e80b.noarch.rpm
MD5: 5acef955bac6fe969b27f4d8e799a00d
SHA-256: 9bf3ef68e9687bb062c25a01d9956f3135705428b90f0fe9a72249ed1329b017
Size: 8.47 kB - npm-11.17.0-1.24.19.0.1.module+el9+1191+8414e80b.noarch.rpm
MD5: 3c0f098697678feb8783c7ca137e703f
SHA-256: a21d6f19af1d297b959bf1641803255222116c879fbe06662fccf396c25df2df
Size: 2.50 MB - v8-13.6-devel-13.6.233.17-1.24.19.0.1.module+el9+1191+8414e80b.x86_64.rpm
MD5: 0623f389aac0c7aff92c60de6729a475
SHA-256: 61bcbf376541452cd29ea821e42e400b61b7fd5fd2b0f389b0c252c5a4a1bd2c
Size: 33.91 kB