Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Fedora 42 nodejs22 Critical DoS Resource Exhaustion Fix 2026-b7ad50870e

fedora
Calendar Grey January 31, 2026
Dist Fedora Esm H88
CVE-2026-22036 and related critical updates for nodejs22 in Fedora 42 ensure safety against various threats.
Update to version 22.22.0

Summary

Node.js is a platform built on Chrome's JavaScript runtime \

for easily building fast, scalable network applications. \

Node.js uses an event-driven, non-blocking I/O model that \

makes it lightweight and efficient, perfect for data-intensive \

real-time applications that run across distributed devices.}

Update Information:

Update to version 22.22.0

Change Log

* Fri Jan 16 2026 Jan Stan\u011bk - 1:22.22.0-2 - Fix c-ares unbundling bits - gate %check section behind a conditional - gate ./configure flag behind a conditional * Tue Jan 13 2026 tjuhasz - 1:22.22.0-1 - Update to version 22.22.0 (rhbz#2428958) * Wed Nov 12 2025 tjuhasz - 1:22.21.1-3 - Rebuild for nodejs-packaging

References


[ 1 ] Bug #2430295 - CVE-2026-22036 nodejs22: Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2430295 [ 2 ] Bug #2431452 - CVE-2025-55132 nodejs22: Nodejs filesystem permissions bypass [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2431452 [ 3 ] Bug #2431459 - CVE-2026-21637 nodejs22: Nodejs denial of service [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2431459 [ 4 ] Bug #2431466 - CVE-2025-59466 nodejs22: Nodejs denial of service [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2431466 [ 5 ] Bug #2431473 - CVE-2025-59464 nodejs22: Nodejs memory leak [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2431473 [ 6 ] Bug #2431484 - CVE-2025-59465 nodejs22: Nodejs denial of service [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2431484 [ 7 ] Bug #...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b7ad50870e' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
critical
Lowest
Low
Medium
High
Critical

Name: nodejs22
Product: Fedora 42
Version: 22.22.0
Release: 2.fc42
Summary: JavaScript runtime

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here