nodejs:24 security, bug fix, and enhancement update

エラータID: AXSA:2026-1972:01

Release date: 
Wednesday, October 7, 2026 - 00:39
Subject: 
nodejs:24 security, bug fix, and enhancement update
Affected Channels: 
Asianux Server 8 for x86_64
Severity: 
High
Description: 

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

* undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation (CVE-2026-85152)
* undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options (CVE-2026-84961)
* undici: undici: Denial of Service via unrequested WebSocket subprotocol (CVE-2026-19534)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

CVE-2026-19534
undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.
CVE-2026-84961
undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2.
CVE-2026-85152
undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2.

Modularity name: "nodejs"
Stream name: "24"

Solution: 

Update packages.

Additional Info: 

N/A

Download: 

SRPMS
  1. nodejs-nodemon-3.1.14-2.module+el8+2051+c5da9083.src.rpm
    MD5: a17e1bc36b86964270b2b89b30c60f22
    SHA-256: afee8a591bf22f2552656a1c9138a5e0640d0eb36424217c177f179a6a830d7c
    Size: 462.03 kB
  2. nodejs-packaging-2021.06-6.module+el8+2051+c5da9083.src.rpm
    MD5: a68e10e2225a040f0002f842dcb99d93
    SHA-256: 4e06d5bb62923931393b23d8448002d86dbfc1f3ef7989fa8f10d6110dd83f2d
    Size: 30.68 kB
  3. nodejs-24.21.0-1.module+el8+2051+c5da9083.src.rpm
    MD5: 608c5b70bc72186a0a8fa0c0a7905660
    SHA-256: 416d83123938221930ab77af13e7fab51efbfe387301488ab8123d5743df1dff
    Size: 101.62 MB

Asianux Server 8 for x86_64
  1. nodejs-24.21.0-1.module+el8+2051+c5da9083.x86_64.rpm
    MD5: 5b07d2b4398303ac60f0590a2fb2ac9a
    SHA-256: b366014f7f9b7c69cb5bf733cbde5171e80541f1e3c22ed902e6fb24286b4825
    Size: 70.24 kB
  2. nodejs-debugsource-24.21.0-1.module+el8+2051+c5da9083.x86_64.rpm
    MD5: f6f4bfd3921292d611e1a02affc1a21e
    SHA-256: 113ac7faf3ce26c57c7cd9a331ef217e82d5d1b76f0c9c0d443efcbfe0d2f8d3
    Size: 24.06 MB
  3. nodejs-devel-24.21.0-1.module+el8+2051+c5da9083.x86_64.rpm
    MD5: 554f6ffc04d8bd2f05c70090d8200811
    SHA-256: aaf35068190dc6b525b2cffd4ae58484807887bfa5e5de2562cf2b56cad4b9f1
    Size: 333.44 kB
  4. nodejs-docs-24.21.0-1.module+el8+2051+c5da9083.noarch.rpm
    MD5: 6af82276d2c90fe7cb8f38254f8f9402
    SHA-256: 9ea1330eda30a625c6c832334fde0a72d93accc90ec0a5b2186a70636b35a9c7
    Size: 6.57 MB
  5. nodejs-full-i18n-24.21.0-1.module+el8+2051+c5da9083.x86_64.rpm
    MD5: 31423a4c652000fec113bdb95e886e61
    SHA-256: 72e6339e975d3a2438ca52e395e06f48a8ef3b92962f3374c54330871d7bd481
    Size: 8.61 MB
  6. nodejs-libs-24.21.0-1.module+el8+2051+c5da9083.x86_64.rpm
    MD5: 6075691ffbed5dec1872634d4c03ef89
    SHA-256: 98d242534467c4a2a122aceff76257e89c5ccec1e9d7897df734d16de8aee88c
    Size: 24.64 MB
  7. nodejs-nodemon-3.1.14-2.module+el8+2051+c5da9083.noarch.rpm
    MD5: f25c6b2cf79b7836515d3037229b95b4
    SHA-256: 8193b8c47fe3136ee19999e1c055bc16eae9900878683c22efdb71992550fd58
    Size: 321.26 kB
  8. nodejs-packaging-2021.06-6.module+el8+2051+c5da9083.noarch.rpm
    MD5: 448fad9199df05f18ab9d14ae14cfd9f
    SHA-256: 8fa3d7d751c86a2c9f1a6242d4cae563a5b84ad4325909418fc1e9711ab105bb
    Size: 24.41 kB
  9. nodejs-packaging-bundler-2021.06-6.module+el8+2051+c5da9083.noarch.rpm
    MD5: df02242a3d07c3a24ea9d980db5c5a28
    SHA-256: ae0826c5589ea4861b8cdaa4335ceaab61e48aa704bf3a8c475b8e0aa360a2af
    Size: 13.99 kB
  10. npm-11.19.0-1.24.21.0.1.module+el8+2051+c5da9083.noarch.rpm
    MD5: 374b096e02d11c5be9cc0a5260d320a1
    SHA-256: 598f4138b59f7a77dd4e2119a499f21177dd2d4169c40ff8bd508273f4e59818
    Size: 2.33 MB
  11. v8-13.6-devel-13.6.233.17-1.24.21.0.1.module+el8+2051+c5da9083.x86_64.rpm
    MD5: 7d35922501bfa6adf970e236f9c57c7e
    SHA-256: 2838d1b27c75bcdd8b3488b898313e1ee11ed9bcbd9cfd97e90fc74240e6df43
    Size: 33.89 kB