[security - high] nodejs:24 security update
エラータID: AXSA:2026-1771:01
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
Security Fix(es):
* nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw (CVE-2026-58043)
* nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks (CVE-2026-56846)
* nodejs: Node.js: Heap-use-after-free in HTTP/2 handling can lead to denial of service (CVE-2026-56848)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-56846
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.
CVE-2026-56848
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
CVE-2026-58043
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
Modularity name: "nodejs"
Stream name: "24"
Update packages.
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
N/A
SRPMS
- nodejs-nodemon-3.1.14-2.module+el8+2039+46434f73.src.rpm
MD5: 4220c9f5e8912fca559b7852791d8243
SHA-256: 88729d9662ae70b842327e7c8327f22f530861a0316448ecf5d9d2e1837d1629
Size: 462.03 kB - nodejs-packaging-2021.06-6.module+el8+2039+46434f73.src.rpm
MD5: ff3566b24ffa074dfcf4a7059bf27bd2
SHA-256: 935f1cdf217ae5aa77db20b41b31852022fbbc337a76e0df962d20220dcd223a
Size: 30.68 kB - nodejs-24.19.0-1.module+el8+2039+46434f73.src.rpm
MD5: 18a1abd26acf80b4acc8585a35eb3c55
SHA-256: 22c8f07bc4d67f6e04308fd5f97c72b95f84012c496deb1db36083e73353581d
Size: 98.64 MB
Asianux Server 8 for x86_64
- nodejs-24.19.0-1.module+el8+2039+46434f73.x86_64.rpm
MD5: 3def4c628ade73d31305d92d6ede4ed7
SHA-256: 205edcb0af8e06a8fd96ab7e37e954bb0268e0567ee4eadcb393411d226688b2
Size: 69.14 kB - nodejs-debugsource-24.19.0-1.module+el8+2039+46434f73.x86_64.rpm
MD5: 09fdf03161caa475f0d8fa39dbd856f0
SHA-256: 89c2b55143410ad700d814e469e971c696827741307aa9bcb234ae9a07e93263
Size: 23.80 MB - nodejs-devel-24.19.0-1.module+el8+2039+46434f73.x86_64.rpm
MD5: 6ebf8a17c516382269c0f97cdf94f031
SHA-256: 06ac78eea82ea07986b6ef315aaea44a1079cff071406f1d7bc6242447c487d9
Size: 333.00 kB - nodejs-docs-24.19.0-1.module+el8+2039+46434f73.noarch.rpm
MD5: 481341c17a96db7988e16d724a6a4931
SHA-256: 67a275e37b7a372cb399113f51b3363c29f039e424aeb6fcaf28156507ccecde
Size: 6.34 MB - nodejs-full-i18n-24.19.0-1.module+el8+2039+46434f73.x86_64.rpm
MD5: e3c22f0c49f94eed7cac658c4bc36eb5
SHA-256: 04b98e3995239498ba02a125dc88ff08499d68a9a310c76bbadb405fe68bd220
Size: 8.61 MB - nodejs-libs-24.19.0-1.module+el8+2039+46434f73.x86_64.rpm
MD5: 4322515c0b1e889883017d87ae2a2eaf
SHA-256: 0b91cef3f547d3b26195448101ab977e8e9074c783e6bca413949307ab65ac96
Size: 24.40 MB - nodejs-nodemon-3.1.14-2.module+el8+2039+46434f73.noarch.rpm
MD5: 290c8d2aacf95127d40d873f82e8536d
SHA-256: 63227914baa21ed1b0e61aeac746d7cd5071116f2ca340eb7d721db5d4a4dfa8
Size: 321.26 kB - nodejs-packaging-2021.06-6.module+el8+2039+46434f73.noarch.rpm
MD5: 97b201fd2948355630dbf6eb934f5844
SHA-256: ce2c86d118395972682c80fabaaf4ecd66b6ff78e03e91b0457f77e74c95a666
Size: 24.41 kB - nodejs-packaging-bundler-2021.06-6.module+el8+2039+46434f73.noarch.rpm
MD5: 5af4b69dce8f81ecafbbe81aba607a2e
SHA-256: 2029accde9d944c35bcd4d9d0e2a8e074c725faa7ef89a784539fb56f953c111
Size: 13.99 kB - npm-11.17.0-1.24.19.0.1.module+el8+2039+46434f73.noarch.rpm
MD5: 49b177263095cf584ca99a5b2972f1d8
SHA-256: 5536cf908117436d5e67fcde65d303e5af56da9f08b3a4895c866ed1beb93f85
Size: 2.31 MB - v8-13.6-devel-13.6.233.17-1.24.19.0.1.module+el8+2039+46434f73.x86_64.rpm
MD5: 05d15f5968424f413ea35d77fa26a43a
SHA-256: 020adf11168f1e3353551f7bd7dace632301ae8bf7913fa742f879cec68d28ba
Size: 33.70 kB