[security - high] nodejs:22 security update
エラータID: AXSA:2026-1464:01
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.
Security Fix(es):
* brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)
* tar: Node-tar: Denial of Service via malformed tar archive header (CVE-2026-59874)
* tar: node-tar: Denial of Service via crafted gzip bomb (CVE-2026-59873)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
CVE-2026-13149
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
CVE-2026-59873
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
CVE-2026-59874
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
Modularity name: "nodejs"
Stream name: "22"
Update packages.
brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
N/A
SRPMS
- nodejs-nodemon-3.1.14-1.module+el8+2019+6a304eab.src.rpm
MD5: 464301da607e586f7ba220aebb43411d
SHA-256: d53fc3d5782edc0d1f3f48769772cfa538876a9b754b8dc5c49210e2e45cbad8
Size: 456.08 kB - nodejs-packaging-2021.06-6.module+el8+2019+6a304eab.src.rpm
MD5: f329341b5bcd797c7ff31cc1afd0f416
SHA-256: 65d6401283a3e173aaabe71da0d0acf9c6c7a731d6f662da4abadcca697e1bb8
Size: 30.99 kB - nodejs-22.23.1-2.module+el8+2019+6a304eab.src.rpm
MD5: 5236dff77ab0d6efc9f31039d718e043
SHA-256: 672da75b4390553f086779472ba0ebb13f0e1b5dc29bd786bffe3dcec0bed8de
Size: 95.33 MB
Asianux Server 8 for x86_64
- nodejs-22.23.1-2.module+el8+2019+6a304eab.x86_64.rpm
MD5: 342ad1edddd020957ac25f000115c110
SHA-256: 42c6788237b85214d3380b7932349586c4e13a00e6fd92570df6b75eff42cc7f
Size: 1.99 MB - nodejs-debugsource-22.23.1-2.module+el8+2019+6a304eab.x86_64.rpm
MD5: b0ecb459ad15915b260151075acaec4e
SHA-256: 97f6850eff17d7abc7254495dd3bd03b848e32543415e89fbd3faf0cec345b8e
Size: 19.95 MB - nodejs-devel-22.23.1-2.module+el8+2019+6a304eab.x86_64.rpm
MD5: 92cd7a1b0995b0fcc207ab50624471dc
SHA-256: 7b73bde5af3269875e45e93a02f2c0cfbf39b6431be74bd3269b5ab68075261a
Size: 269.24 kB - nodejs-docs-22.23.1-2.module+el8+2019+6a304eab.noarch.rpm
MD5: d0a97b1efd82952c426ac85d8138810b
SHA-256: 740b722d0aa8642ceebb4f42afcd476b003f13f1ff39d98b61a13e971ac0fd8d
Size: 11.69 MB - nodejs-full-i18n-22.23.1-2.module+el8+2019+6a304eab.x86_64.rpm
MD5: b1c5dd185fed3c69326c71ec990a83da
SHA-256: 5a9ff3850ef4cd70ab6f67baf787e723d2c21ab0488a5903eaf5eb652253946f
Size: 8.60 MB - nodejs-libs-22.23.1-2.module+el8+2019+6a304eab.x86_64.rpm
MD5: 4d6e47261cf1698ded74835826274897
SHA-256: 9b23cc8cd583081f1c94222e64e2daad4c27d7ec1b92c40d5e41a9638a927d13
Size: 20.72 MB - nodejs-nodemon-3.1.14-1.module+el8+2019+6a304eab.noarch.rpm
MD5: 702f5ae61da126b1dbc829d718832c44
SHA-256: 822ac8692750dcfb53b3e374797dfc9791d99868c834284f9051a67a699c9e06
Size: 320.12 kB - nodejs-packaging-2021.06-6.module+el8+2019+6a304eab.noarch.rpm
MD5: 6a8989eaac61ead389c651cb197f4bf0
SHA-256: db790f0aa62716b02db4dbab43d001ad649fddbddb66eb925302b8cb1a4a7372
Size: 24.51 kB - nodejs-packaging-bundler-2021.06-6.module+el8+2019+6a304eab.noarch.rpm
MD5: 3beeb5f27776f2c72367a749590d9efd
SHA-256: de6134884b3144ccc1bca5b6e783b87f8ccf25349348021ba04fcc528d851edd
Size: 14.10 kB - npm-10.9.8-1.22.23.1.2.module+el8+2019+6a304eab.x86_64.rpm
MD5: 5b61d3cad5b24df607eaaedb92cea856
SHA-256: d1ef3c5f3cb7267ff532a87e701bc0cdd80cfb4a0a70ba48c149c9fdd0c53b34
Size: 2.15 MB - v8-12.4-devel-12.4.254.21-1.22.23.1.2.module+el8+2019+6a304eab.x86_64.rpm
MD5: f18d4805c5f04d32f1c77bd39502792b
SHA-256: b0602a5d8a8f706cfdf57c55a364f097a3d2cbd9d78e4ee0dc9fdc80617cabd9
Size: 15.67 kB