AlmaLinux alert ALSA-2026:7123 (nodejs:22)
| From: | AlmaLinux Errata Notifications via Announce <announce@lists.almalinux.org> | |
| To: | announce@lists.almalinux.org | |
| Subject: | [Announce] [Security Advisory] ALSA-2026:7123: nodejs:22 security update (Important) | |
| Date: | Wed, 15 Apr 2026 15:15:49 +0000 | |
| Message-ID: | <0100019d91b67cc4-62eb9c5d-bffa-4bd1-9bb4-ca41b5a32b13-000000@email.amazonses.com> | |
| Archive-link: | Article |
Hi, You are receiving an AlmaLinux Security update email because you subscribed to receive errata notifications from AlmaLinux. AlmaLinux: 8 Type: Security Severity: Important Release date: 2026-04-15 Summary: Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * brace-expansion: brace-expansion: Denial of Service via unbounded brace range expansion (CVE-2026-25547) * minimatch: minimatch: Denial of Service via specially crafted glob patterns (CVE-2026-26996) * minimatch: Minimatch: Denial of Service via catastrophic backtracking in glob expressions (CVE-2026-27904) * undici: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression (CVE-2026-1526) * undici: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter (CVE-2026-2229) * undici: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers (CVE-2026-1525) * undici: undici: Denial of Service via crafted WebSocket frame with large length (CVE-2026-1528) * nghttp2: nghttp2: Denial of Service via malformed HTTP/2 frames after session termination (CVE-2026-27135) * Node.js: Node.js: Denial of Service due to crafted HTTP `__proto__` header (CVE-2026-21710) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Full details, updated packages, references, and other related information: https://errata.almalinux.org/8/ALSA-2026-7123.html This message is automatically generated, please don’t reply. For further questions, please, contact us via the AlmaLinux community chat: https://chat.almalinux.org/. Want to change your notification settings? Sign in and manage mailing lists on https://lists.almalinux.org. Kind regards, AlmaLinux Team _______________________________________________ Announce mailing list -- announce@lists.almalinux.org To unsubscribe send an email to announce-leave@lists.almalinux.org
