Red Hat released Important security updates for Node.js 24 across RHEL 8, RHEL 9, and RHEL 10, rebasing packages to Node.js 24.14.1 and fixing multiple flaws in Node.js and bundled components including undici, nghttp2, brace-expansion, minimatch, and V8. The advisories cover a broad set of impacts, including denial of service, information disclosure, HTTP header injection, HTTP request smuggling, permission bypass, and weaknesses affecting local inter-process communication. Affected builds span major RHEL architectures including x86_64, s390x, ppc64le, and aarch64, along with extended support variants.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Red Hat disclosed that brace-expansion through 5.0.7 is vulnerable to denial of service via memory exhaustion in expand(), fixed in version 5.0.8 with a new maxLength option. The Bugzilla reference states Red Hat addressed the issue in Red Hat Enterprise Linux 8, 9, and 10 and published multiple advisories for affected products.
Red Hat disclosed CVE-2026-9678 in Undici, where improper parsing of whitespace-padded Cache-Control qualified field names can cause authenticated responses to be cached and later served to other callers in shared-cache mode. The Bugzilla entry states Red Hat addressed the issue through advisories for Red Hat Enterprise Linux 8, 9, and 10.
On 2026-04-13, Red Hat published RHSA-2026:7675, an Important security advisory for nodejs24 on Red Hat Enterprise Linux 10. The update delivered nodejs24 version 24.14.1-2.el10_1 and fixed multiple vulnerabilities in Node.js and bundled components including undici, nghttp2, brace-expansion, minimatch, and V8.
On 2026-04-13, Red Hat published RHSA-2026:7670, an Important security advisory for the nodejs:24 module on Red Hat Enterprise Linux 8. The update rebased Node.js to 24.14.1 and addressed multiple denial-of-service, request smuggling, information disclosure, permission bypass, and IPC-related flaws.
On 2026-04-09, Red Hat published RHSA-2026:7350, an Important security advisory for the nodejs:24 module on Red Hat Enterprise Linux 9. The update rebased Node.js to 24.14.1 and fixed multiple vulnerabilities across Node.js and bundled components including undici, brace-expansion, minimatch, nghttp2, and V8.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
bugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.