Red Hat released Important security updates for Node.js packages across RHEL 8, 9, and 10 to fix three denial-of-service vulnerabilities in bundled components: CVE-2026-13149 in brace-expansion, CVE-2026-59873 in node-tar, and CVE-2026-59874 in node-tar/tar. The advisories cover multiple product streams, including nodejs:24 on RHEL 8 and 9, nodejs22 and nodejs24 on RHEL 10, and nodejs:22 for RHEL 9.6 Extended Update Support, with updated packages such as Node.js 22.23.1 and 24.18.0 distributed across standard, EUS, and ELC channels.
The flaws could let attackers trigger excessive resource consumption through crafted input during archive handling or pattern expansion. In brace-expansion, consecutive non-expanding {} groups can drive exponential-time processing and block the event loop; in node-tar, a crafted gzip bomb can exhaust CPU and disk during extraction or parsing, while a malformed tar header with a negative base-256 entry size can cause the scanner to repeatedly parse the same header without making progress. Red Hat tracked the issues in Bugzilla and published remediation through advisories including RHSA-2026:47060, RHSA-2026:47057, RHSA-2026:48033, RHSA-2026:48034, RHSA-2026:52399, and RHSA-2026:53298.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
Red Hat published RHSA-2026:53298 for nodejs22 on RHEL 10.0 Extended Update Support, addressing CVE-2026-13149 and the two node-tar denial-of-service issues. The advisory provided updated nodejs22 22.23.1-3.el10_0 packages for x86_64, s390x, ppc64le, and aarch64.
Red Hat published RHSA-2026:52399 for the nodejs:22 module in RHEL 9.6 Extended Update Support, including fixes for CVE-2026-13149, CVE-2026-59873, and CVE-2026-59874 among other vulnerabilities. The update shipped Node.js 22.23.1-2.module+el9.6.0+24604+449f851b packages across multiple architectures and service channels.
Red Hat published RHSA-2026:48034 for nodejs24 on RHEL 10, fixing the same three denial-of-service vulnerabilities in brace-expansion and node-tar. Updated nodejs24 24.18.0-3.el10_2 packages were released for multiple RHEL 10 variants and architectures.
Red Hat published RHSA-2026:48033 for nodejs22 on RHEL 10, remediating CVE-2026-13149 and the two node-tar denial-of-service flaws. The advisory provided updated Node.js 22.23.1-4.el10_2 packages for multiple RHEL 10 architectures and support channels.
Red Hat published RHSA-2026:47057 for the nodejs:24 module on RHEL 9, addressing the brace-expansion and node-tar denial-of-service vulnerabilities. The update shipped Node.js 24.18.0-3 module packages across standard RHEL 9 and related support channels.
Red Hat published RHSA-2026:47060 for the nodejs:24 module on RHEL 8, fixing CVE-2026-13149 in brace-expansion and CVE-2026-59873/CVE-2026-59874 in node-tar. Updated Node.js 24.18.0-2 module packages were released for multiple RHEL 8 architectures and Extended Life Cycle 8.10 offerings.
Red Hat's OSIDB/Bzimport reported CVE-2026-59874 in Bugzilla as a high-severity node-tar denial-of-service vulnerability. The flaw involves tar.replace repeatedly parsing a checksum-valid header with a negative base-256 encoded entry size, affecting versions prior to 7.5.18.
Red Hat's OSIDB/Bzimport created the Bugzilla record for CVE-2026-59873, tracking a node-tar denial-of-service issue caused by a crafted gzip bomb. The record notes the flaw affects node-tar versions prior to 7.5.19.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
9 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.