Red Hat released Important security updates for Node.js packages across RHEL 8, 9, and 10, covering nodejs:22, nodejs:24, and nodejs22 builds affected by vulnerabilities in bundled or related components. The advisories address CVE-2026-69192 in the ip-address JavaScript library, where inconsistent parsing of IPv4 octets with leading zeros can cause applications to treat internal addresses as external, enabling server-side request forgery (SSRF) and trust-boundary bypass. Red Hat published errata including RHSA-2026:54371, RHSA-2026:54530, RHSA-2026:55601, RHSA-2026:55603, and RHSA-2026:55541 for affected RHEL product streams and architectures.
The updates also fix CVE-2026-69152, a high-severity denial-of-service flaw in brace-expansion that can exhaust memory or block the Node.js event loop through unbounded intermediate arrays, bypassing an earlier mitigation for CVE-2026-14257. Several advisories additionally include fixes for SQLite FTS5 arbitrary code execution issues bundled with Node.js-related packages. Red Hat said the ip-address issue is fixed in version 10.3.1, while affected brace-expansion releases are corrected in versions prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, with updated Node.js, npm, and related development packages now available for supported RHEL platforms.

See real exploitation activity before you spend the cycle.
24 events from the most recent confirmed update back to the earliest known activity.
On 2026-09-02, Red Hat published Important-rated RHSA-2026:62416 for the nodejs:22 package on Red Hat Enterprise Linux 9. The update fixes nine vulnerabilities, including SQLite FTS5 flaws, brace-expansion and ip-address issues, Node.js HTTP/2 denial-of-service vulnerabilities CVE-2026-56846 and CVE-2026-56848, and the permission-model filesystem-access flaw CVE-2026-58043.
On 2026-08-31, Red Hat issued RHSA-2026:61374, rated Important, to update nodejs-nodemon on Red Hat Enterprise Linux 10 for CVE-2026-69152. The brace-expansion flaw can cause denial of service through unbounded intermediate arrays and bypasses mitigation for CVE-2026-14257.
On 2026-08-25, Rocky Linux published RLSA-2026:54530 for Node.js-related packages in Rocky Linux 8. The update addresses CVE-2026-11822 and CVE-2026-11824 in SQLite FTS5, CVE-2026-14257 and CVE-2026-69152 in brace-expansion, and CVE-2026-69192 in ip-address.
On 2026-08-25, Rocky Linux published advisory RLSA-2026:58819 for nodejs24 packages on Rocky Linux 10. The update addresses CVE-2026-14257 and CVE-2026-69152 in brace-expansion and CVE-2026-54272 and CVE-2026-69192 in ip-address.
On 2026-08-24, AlmaLinux published advisory ALSA-2026:58819 for AlmaLinux 10 covering nodejs24 packages. The update addresses CVE-2026-14257, CVE-2026-54272, CVE-2026-69152, and CVE-2026-69192 and maps to Red Hat advisory RHSA-2026:58819.
On 2026-08-24, Red Hat published RHSA-2026:58819 for nodejs24 on Red Hat Enterprise Linux 10.2. The advisory fixes multiple bundled-component vulnerabilities, including CVE-2026-14257 and CVE-2026-69152 in brace-expansion and CVE-2026-54272 and CVE-2026-69192 in ip-address.
On 2026-08-17, Red Hat published RHSA-2026:55541 for nodejs22 in Red Hat Enterprise Linux 10. The advisory fixes CVE-2026-69152 in brace-expansion and CVE-2026-69192 in ip-address.
On 2026-08-17, Red Hat published RHSA-2026:55603 for the nodejs:24 module in Red Hat Enterprise Linux 9. The advisory includes fixes for CVE-2026-69152 and CVE-2026-69192 as part of a broader Node.js security update.
On 2026-08-17, Red Hat published RHSA-2026:55601 for the nodejs:22 module in Red Hat Enterprise Linux 9. The update addresses CVE-2026-69152 in brace-expansion and CVE-2026-69192 in ip-address, along with SQLite issues.
TencentOS Server 3 published TSSA-2026:0921 for affected nodejs-nodemon and nodejs-packaging packages, addressing CVE-2026-11822, CVE-2026-11824, CVE-2026-14257, CVE-2026-69152, and CVE-2026-69192. The associated Nessus check reports that exploits are available for the identified vulnerabilities.
On 2026-08-13, Red Hat published RHSA-2026:54530 for the nodejs:22 module in Red Hat Enterprise Linux 8. The advisory fixes CVE-2026-69152 in brace-expansion and CVE-2026-69192 in ip-address, among other vulnerabilities.
On 2026-08-12, Red Hat published RHSA-2026:54371 for the nodejs:24 module in Red Hat Enterprise Linux 8. The advisory includes fixes for CVE-2026-69152 in brace-expansion and CVE-2026-69192 in ip-address, along with other bundled-component vulnerabilities.
Red Hat documented CVE-2026-54272 in bug 2507593, describing an SSRF flaw in ip-address caused by misclassification of IPv4-mapped and NAT64 IPv6 addresses. The bug states affected versions are 10.1.1 through 10.2.0 and that the issue was fixed in ip-address 10.2.1.
Red Hat tracked CVE-2026-69152 as bug 2510722, describing a high-severity denial-of-service flaw in brace-expansion caused by unbounded intermediate arrays that can exhaust memory or block the event loop. The bug entry states it was reported by OSIDB Bzimport on 2026-08-03 18:01 UTC.
Red Hat documented CVE-2026-12151 in bug 2489980, describing a denial-of-service flaw in undici's WebSocket client caused by unbounded memory growth from fragmented WebSocket messages. The bug notes affected undici releases start at 6.17.0 and that fixes are available in undici 6.26.0, 7.28.0, and 8.5.0 or later.
On 2026-07-06, Red Hat published RHSA-2026:35841 for nodejs24 on Red Hat Enterprise Linux 10, rebasing the package to Node.js 24.18.0-1.el10_2. The advisory fixes multiple vulnerabilities in Node.js and bundled components including undici and ip-address, among them CVE-2026-42338.
On 2022-12-06, Red Hat published RHSA-2022:8832 for the RHEL 9 nodejs:18 module, upgrading Node.js to version 18.12.1. The Moderate-rated update fixes CVE-2022-3517, a ReDoS issue in nodejs-minimatch's braceExpand function, and CVE-2022-43548, a DNS-rebinding weakness involving invalid octal IP addresses in Node.js inspect.
Node.js released version 14.21.1 to remediate CVE-2022-43548, a DNS-rebinding issue in inspect involving invalid octal IP addresses.
Red Hat documented CVE-2026-11822 in bug 2487258, describing an out-of-bounds read in fts5LeafSeek() and a heap buffer overflow in fts5ChunkIterate() affecting SQLite FTS5 before 3.53.2. A crafted SQLite database can trigger the flaws when an FTS5 MATCH query is executed, potentially causing crashes, memory exhaustion, or arbitrary code execution.
Red Hat documented CVE-2026-11824, a heap-based buffer overflow in SQLite FTS5 versions before 3.53.2. A crafted database with malicious continuation-page metadata can trigger an integer underflow during an FTS5 MATCH query, potentially causing a crash or arbitrary code execution in applications built with SQLITE_ENABLE_FTS5.
Red Hat documented CVE-2026-69192 in bug 2510801, describing inconsistent IPv4 parsing in the ip-address library that can let leading-zero octets bypass SSRF and trust-boundary checks. The bug notes the issue is fixed in ip-address version 10.3.1.
Red Hat documented CVE-2026-42338 in bug 2476810, describing a cross-site scripting flaw in ip-address where Address6.group(), Address6.link(), and one AddressError.parseMessage path can return unescaped attacker-controlled HTML. The bug states the issue affects versions prior to 10.1.1 and was fixed in ip-address 10.1.1.
Red Hat tracked CVE-2024-4068, a denial-of-service vulnerability in the npm braces package. Crafted imbalanced-brace input can cause its parser to repeatedly allocate JavaScript heap memory until the affected process exhausts memory and crashes; Red Hat issued fixes for several products including Migration Toolkit for Containers, JBoss EAP, Advanced Cluster Management, Multicluster Engine, and HawtIO.
Red Hat addressed the nodejs-minimatch braceExpand ReDoS vulnerability, CVE-2022-3517, through additional advisories for RHEL 8, RHEL 7 Software Collections, Advanced Cluster Management, Migration Toolkit for Runtimes, and RHODF. The flaw affects minimatch versions before 3.0.5 and was fixed upstream in commit a8763f4388e51956be62dc6025cec1126beeb5e6.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
24 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourcetenable.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourcebugzilla.redhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.