nodejs:24 security, bug fix, and enhancement update
エラータID: AXSA:2026-1984:01
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
Security Fix(es):
* undici: undici: Authentication bypass via cross-origin cache poisoning due to missing origin isolation (CVE-2026-85152)
* undici: undici: TLS certificate validation bypass in BalancedPool via dropped connect options (CVE-2026-84961)
* undici: undici: Denial of Service via unrequested WebSocket subprotocol (CVE-2026-19534)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-19534
undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.
CVE-2026-84961
undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2.
CVE-2026-85152
undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2.
Modularity name: "nodejs"
Stream name: "24"
Update packages.
undici's WebSocket client crashes the whole Node.js process during the opening handshake when a server responds with a subprotocol that the client never requested. A default WebSocket connection sends no subprotocol, but if the server's 101 response includes a Sec-WebSocket-Protocol header, undici dereferences a null value while checking it against the requested list and throws an uncaught TypeError. Because that code runs inside a microtask with no surrounding error handling, the exception propagates and terminates the process under Node's default behavior, instead of gracefully failing the connection as required by the WebSocket protocol. Any application that opens a WebSocket to an attacker-controlled or compromised server, or over a plaintext connection subject to a machine-in-the-middle, can be crashed remotely without authentication in the default configuration. This affects undici versions from 6.7.0 up to 6.28.1, from 7.0.0 up to 7.29.1, and from 8.0.0 up to 8.10.2. Users should upgrade to undici 6.28.1, 7.29.1, or 8.10.2.
undici's BalancedPool constructor passes its entire options object through an internal deep-clone that serializes and reparses the value as JSON. Because JSON cannot represent functions, any function-valued TLS option, such as a caller-supplied checkServerIdentity callback or a custom connector inside the connect option, is silently discarded before it reaches the TLS layer. As a result a peer whose certificate the application's custom checkServerIdentity was written to reject, but which still passes Node's default hostname and chain checks, is accepted when reached through BalancedPool. The Client, Pool, and Agent dispatchers are not affected because they extract the connect and tls options before cloning. This affects undici versions from 7.24.1 up to 7.29.1 and from 8.0.0 up to 8.10.2, and only when the application supplies a function-valued connect or tls option to BalancedPool. Users should upgrade to undici 7.29.1 or 8.10.2.
undici 8.10.0 omits the destination origin from the cache and request-deduplication keys when the cache or deduplicate interceptor is composed directly onto a Client or Pool. Because the internal cache key falls back to an empty origin string, a cacheable or in-flight response from one upstream origin is returned for a request to a different, trusted origin whenever the method, path, and relevant headers match, which permits cross-origin information disclosure and persistent cache poisoning. The reporter demonstrated a full authentication bypass in which a JWT signed with an attacker-controlled key was accepted as belonging to a trusted issuer, and the trusted origin was never contacted. This is a regression introduced in 8.10.0 and affects undici versions from 8.10.0 up to 8.10.2. Applications using an Agent, which carries the origin in its dispatch options, are not affected. Users should upgrade to undici 8.10.2.
N/A
SRPMS
- nodejs-nodemon-3.1.14-3.module+el9+1203+81807fc1.src.rpm
MD5: c61fe452d126999979638f4d252d8b80
SHA-256: a2d1bfd982d6740e1cc109428f227aebc1be778cd5773885f01793e5137824c5
Size: 462.94 kB - nodejs-packaging-2021.06-6.module+el9+1203+81807fc1.src.rpm
MD5: 7bb37a341b987b2be96e2ac14e193f0b
SHA-256: 8e41e046f8caa7acab53d29280bc678f6f15c4215708797b9098d7018ea9e0e0
Size: 25.40 kB - nodejs-24.21.0-1.module+el9+1203+81807fc1.src.rpm
MD5: 2ba1b9688728a731c91dc406bdc05a3a
SHA-256: 9e760184e3d7f13682e0aacf8282a6d506fd85f6f996968be1aadb5cff3cfc14
Size: 101.62 MB
Asianux Server 9 for x86_64
- nodejs-24.21.0-1.module+el9+1203+81807fc1.x86_64.rpm
MD5: 02ced60201164b48c54d59f27f9d5841
SHA-256: 10b13728bb5e18b6fe031efab64cd9ff57da63864ce2a2d4a15ff64163707642
Size: 69.64 kB - nodejs-debugsource-24.21.0-1.module+el9+1203+81807fc1.x86_64.rpm
MD5: 6b8a3cdfec2215f8f70d0c8705eabfe3
SHA-256: 4aa842bb4274ecd59711fc97b7f8479c3556a5af7f2de01c499b1252afb847b0
Size: 21.25 MB - nodejs-devel-24.21.0-1.module+el9+1203+81807fc1.x86_64.rpm
MD5: 54ac11cc0ac7d6895bd3cd28d414ace7
SHA-256: d6a090cc3b2349ddffda2f1c0d188a372cfa4a9feba1bbcebbe24b6bc5508dd6
Size: 336.12 kB - nodejs-docs-24.21.0-1.module+el9+1203+81807fc1.noarch.rpm
MD5: 60cd7cce861fbf0387ba5cc6d267fe1c
SHA-256: 77c3743f3e8c7577c12ee2fdfa1a918b12df658a2470b536bcd3bbce4ac4141e
Size: 5.40 MB - nodejs-full-i18n-24.21.0-1.module+el9+1203+81807fc1.x86_64.rpm
MD5: 62ce09288b109ba90d151f7ee375a7ae
SHA-256: 5fa8c81cd6b0afe6e7e5e028e3259a0d45d2bb957926411729b2e648d11cd174
Size: 8.87 MB - nodejs-libs-24.21.0-1.module+el9+1203+81807fc1.x86_64.rpm
MD5: 490b8fa15bccbffd0b99875a368500d0
SHA-256: 006c68cbe344317e72404b802771654b72cdd4e26a6e93ab9928410312157915
Size: 23.74 MB - nodejs-nodemon-3.1.14-3.module+el9+1203+81807fc1.noarch.rpm
MD5: 183a75b5a98797c9bbe8f44f06e256f9
SHA-256: ffbbcb0e4f6a87df69ee1524d8735909795dc0250da08fe671fdf74fa9690b1f
Size: 376.05 kB - nodejs-packaging-2021.06-6.module+el9+1203+81807fc1.noarch.rpm
MD5: 4f9595f192f1f414f1ab77c651b4979d
SHA-256: 0c75d154d93973b04db5a3ac7c182427e3e4681a0351c2da866bfe452b469e74
Size: 18.66 kB - nodejs-packaging-bundler-2021.06-6.module+el9+1203+81807fc1.noarch.rpm
MD5: 5d9e201374b3fa7e4fa02f2ca007b0de
SHA-256: 7053cac5ca64490a9a0a15500312ba4b3fdfd60a8475e16403fab3e146626b39
Size: 8.47 kB - npm-11.19.0-1.24.21.0.1.module+el9+1203+81807fc1.noarch.rpm
MD5: 3fe04c6ba0875bcc84f86061d486c410
SHA-256: 2a13acd1cbc549425320343a4a42abbc95969dc9d45c2279213ad4907ee91601
Size: 2.52 MB - v8-13.6-devel-13.6.233.17-1.24.21.0.1.module+el9+1203+81807fc1.x86_64.rpm
MD5: 2655962e0f3273d05612998b7c512ea9
SHA-256: 762b936d51c1cf2cef1308f148b2f315597f712a6b158d3e20cc6ed4352cb3bd
Size: 33.96 kB