Red Hat released Important security updates for Node.js 22 across RHEL 8, RHEL 9, RHEL 9.6 EUS, and RHEL 10, rebasing affected packages to Node.js 22.22.2 and updating related RPMs for x86_64, aarch64, ppc64le, and s390x. The advisories cover multiple vulnerabilities in Node.js and bundled components including brace-expansion, minimatch, undici, and nghttp2, with impacts dominated by denial-of-service conditions and one HTTP request smuggling flaw tied to duplicate Content-Length headers in undici.
The fixes span a set of CVEs including CVE-2026-25547, CVE-2026-26996, CVE-2026-27904, CVE-2026-1525, CVE-2026-1526, CVE-2026-1528, CVE-2026-2229, CVE-2026-27135, and CVE-2026-21710. Red Hat’s Bugzilla entry for CVE-2026-25547 says the brace-expansion package could be abused through unbounded brace range expansion, causing exponential CPU and memory consumption and potentially crashing Node.js processes; the issue was patched upstream in version 5.0.1 and incorporated into Red Hat’s errata for supported RHEL releases and lifecycle channels.

See real exploitation activity before you spend the cycle.
14 events from the most recent confirmed update back to the earliest known activity.
On 2026-08-10, Red Hat published RHSA-2026:52399, an Important advisory for the nodejs:22 module in Red Hat Enterprise Linux 9.6 Extended Update Support and related channels. The update delivers Node.js 22.23.1 packages that fix eight vulnerabilities, including flaws in ip-address, undici, Node.js WebCrypto, Node.js itself, brace-expansion, and node-tar.
On 2026-07-28, Red Hat published RHSA-2026:47059, an Important advisory for the nodejs:22 module in Red Hat Enterprise Linux 8. The update delivers Node.js 22.23.1 packages that fix denial-of-service vulnerabilities in brace-expansion and tar/node-tar, including CVE-2026-13149, CVE-2026-59873, and CVE-2026-59874.
On 2026-07-20, Red Hat published RHSA-2026:41947, an Important advisory for the nodejs:22 module in Red Hat Enterprise Linux 8. The update rebases Node.js 22 to version 22.23.1 and fixes multiple vulnerabilities across Node.js, undici, and ip-address, including denial-of-service, information disclosure, authentication bypass, certificate validation bypass, trust-policy bypass, response queue poisoning, SameSite cookie parsing weakness, cross-site scripting, and unauthorized file metadata modification flaws.
On 2026-07-15, Red Hat published RHSA-2026:39868, an Important advisory for the nodejs:24 module in Red Hat Enterprise Linux 8. The update rebases Node.js to 24.18.0 and fixes multiple vulnerabilities across Node.js, undici, and ip-address, including denial-of-service, information disclosure, authentication bypass, certificate validation bypass, trust-policy bypass, response queue poisoning, man-in-the-middle risk, cross-site scripting, and unauthorized file metadata modification flaws.
On 2026-07-14, Red Hat published RHSA-2026:39246, an Important advisory for nodejs22 on Red Hat Enterprise Linux 10.0. The update provides Node.js 22.23.1-2.el10_0 packages that fix five vulnerabilities across ip-address, undici, Node.js WebCrypto, and Node.js, including cross-site scripting, denial-of-service, information disclosure, and authentication bypass flaws.
On 2026-07-06, Red Hat published RHSA-2026:35892, an Important advisory for the nodejs:22 module in Red Hat Enterprise Linux 9. The update rebases Node.js to 22.23.1 and fixes multiple vulnerabilities across Node.js, undici, and ip-address, including denial-of-service, information disclosure, authentication bypass, certificate validation bypass, trust-policy bypass, response queue poisoning, SameSite cookie parsing weakness, cross-site scripting, and unauthorized file metadata modification flaws.
On 2026-07-06, Red Hat published RHSA-2026:35842, an Important advisory for nodejs22 on Red Hat Enterprise Linux 10. The update rebases nodejs22 to Node.js 22.23.1-2.el10_2 and fixes multiple vulnerabilities in Node.js, undici, and ip-address, including denial-of-service, information disclosure, authentication bypass, certificate validation bypass, trust-policy bypass, and cross-site scripting flaws.
On 2026-04-14, Red Hat published RHSA-2026:7983, an Important advisory for the nodejs:22 module in Red Hat Enterprise Linux 9.6 Extended Update Support and related channels. The update delivers Node.js 22.22.2 packages to fix multiple denial-of-service vulnerabilities and an undici HTTP request smuggling issue.
On 2026-04-09, Red Hat published RHSA-2026:7310, an Important advisory for nodejs22 in Red Hat Enterprise Linux 10.0. The nodejs22-22.22.2-2.el10_0 update fixes the same set of Node.js ecosystem flaws, including several denial-of-service issues and an undici request-smuggling bug.
On 2026-04-09, Red Hat published RHSA-2026:7302, an Important advisory for the nodejs:22 module in Red Hat Enterprise Linux 9. The update provides Node.js 22.22.2 packages that remediate multiple vulnerabilities across brace-expansion, minimatch, undici, nghttp2, and Node.js itself.
On 2026-04-08, Red Hat published RHSA-2026:7123, an Important advisory for the nodejs:22 module in Red Hat Enterprise Linux 8. The update rebases nodejs:22 to Node.js 22.22.2 and fixes multiple denial-of-service flaws plus an undici HTTP request smuggling issue.
On 2026-04-08, Red Hat published RHSA-2026:7080, an Important advisory for nodejs22 on Red Hat Enterprise Linux 10. The update to Node.js 22.22.2-1.el10_1 fixes multiple vulnerabilities in Node.js, brace-expansion, minimatch, undici, and nghttp2, including an undici request-smuggling issue.
Red Hat Bugzilla recorded CVE-2026-25547, a brace-expansion denial-of-service flaw caused by unbounded brace range expansion. The bug entry says the issue was reported by OSIDB Bzimport on 2026-02-04 22:01 UTC.
The Bugzilla record states that CVE-2026-25547 was patched in @isaacs/brace-expansion version 5.0.1. No explicit release date for version 5.0.1 is provided in the content.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
13 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.