[security - high] nodejs:22 security update
エラータID: AXSA:2026-1753:01
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
Security Fix(es):
* nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw (CVE-2026-58043)
* nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks (CVE-2026-56846)
* nodejs: Node.js: Heap-use-after-free in HTTP/2 handling can lead to denial of service (CVE-2026-56848)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-56846
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.
CVE-2026-56848
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
CVE-2026-58043
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
Modularity name: "nodejs"
Stream name: "22"
Update packages.
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
N/A
SRPMS
- nodejs-nodemon-3.1.14-2.module+el8+2036+1c70fb10.src.rpm
MD5: e943d51e099ba357d8724d05c521ceac
SHA-256: 1730ef89356b72c388d60e395fc89986b5ac695e74c48ab561c9c5094cd3876b
Size: 464.96 kB - nodejs-packaging-2021.06-6.module+el8+2036+1c70fb10.src.rpm
MD5: 08229e3fc988f77b780a41d0593de00d
SHA-256: 65cab65a075ebbecb925c83e1d30d5fa60afaf17065c409c623fbef0a992da38
Size: 30.99 kB - nodejs-22.23.2-1.module+el8+2036+1c70fb10.src.rpm
MD5: 05b77fed9bc5314ac0803b6e965b2f3c
SHA-256: d8feee65bfe4127725e6861f07f401fb4dab055c926b1751d1931dda6bf6fa0c
Size: 95.48 MB
Asianux Server 8 for x86_64
- nodejs-22.23.2-1.module+el8+2036+1c70fb10.x86_64.rpm
MD5: 84bfc066e5253a63448ce12be7101e42
SHA-256: 7eade10ea328b986b6ffe6d8c0edc812de49bd80cc194eb0faacc88962ce0af4
Size: 1.99 MB - nodejs-debugsource-22.23.2-1.module+el8+2036+1c70fb10.x86_64.rpm
MD5: 9fe28283b1fd3f542ca9702634e0f14f
SHA-256: a3dc65f5a625216f713d2fae3e81600406db2438101383a81be340b5080fa934
Size: 19.99 MB - nodejs-devel-22.23.2-1.module+el8+2036+1c70fb10.x86_64.rpm
MD5: 685900e2009a1d0e8b4126f4666cb435
SHA-256: 5c0987bd91083766b779c85417f3bd183e209ac098077bb07e7d7d9b7fa65b7b
Size: 269.77 kB - nodejs-docs-22.23.2-1.module+el8+2036+1c70fb10.noarch.rpm
MD5: 7f682f5ced1037338c96dafdc93932b4
SHA-256: 9af4dcac145fee0b2bbe47803d170fafac489f7534db9dcb6a3451e2a7a8b93c
Size: 11.69 MB - nodejs-full-i18n-22.23.2-1.module+el8+2036+1c70fb10.x86_64.rpm
MD5: b2e0f97619ef96912204f2748fa360b4
SHA-256: 06b100a5c9dcb197b4a16618c3c694f38c4c281724ea7d1688e3801398d15840
Size: 8.60 MB - nodejs-libs-22.23.2-1.module+el8+2036+1c70fb10.x86_64.rpm
MD5: 677499d83fb9a9600b20d2ca28ead240
SHA-256: 67812ee3758f271604fdae57814da6816d3bc78202132448017690d9623b8cde
Size: 20.73 MB - nodejs-nodemon-3.1.14-2.module+el8+2036+1c70fb10.noarch.rpm
MD5: 68d5250e9b64e00df838f9b41fe2d306
SHA-256: 452dc9e4e9460df58c63f5ed8fea14d3956aebcff5d3754d905fcf5569e3578e
Size: 322.46 kB - nodejs-packaging-2021.06-6.module+el8+2036+1c70fb10.noarch.rpm
MD5: 38e49ad03dbe932405e12a1f9173f441
SHA-256: 5ca50cd05bff034e9c6ea9a8fc99161d8245c5184c98906fe13dd1c9a4cb3403
Size: 24.51 kB - nodejs-packaging-bundler-2021.06-6.module+el8+2036+1c70fb10.noarch.rpm
MD5: 8dbe742edd8681e82a563c868b55e0ec
SHA-256: f1a69eaa454a5062c41c7d9af6b564ba25f7690be11abd675277f5f4e89ea453
Size: 14.10 kB - npm-10.9.8-1.22.23.2.1.module+el8+2036+1c70fb10.x86_64.rpm
MD5: 8f283be90e03567811e2f94c67a4ccd6
SHA-256: d724c010ae2f62935f5a1b625342a9741412c7a584e48d41af0685bd05e0f8ba
Size: 2.16 MB - v8-12.4-devel-12.4.254.21-1.22.23.2.1.module+el8+2036+1c70fb10.x86_64.rpm
MD5: 97d5c6c92ce864a7d330c17521f95559
SHA-256: 3167c7b3ae9f9b83546355ddd016fb5c88308cafd7a1c16382c3c0ca01258e31
Size: 16.21 kB