Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Fedora 43 Nodejs24 Update for Resource Exhaustion DoS 2026-5cd409edfa

fedora
Calendar Grey January 31, 2026
Scroller Fedora
Node.js version 24.13.0 update for Fedora 43 addresses multiple security concerns, including resource exhaustion.
Update to version 24.13.0

Summary

Node.js is a platform built on Chrome's JavaScript runtime

for easily building fast, scalable network applications.

Node.js uses an event-driven, non-blocking I/O model that

makes it lightweight and efficient, perfect for data-intensive

real-time applications that run across distributed devices.

Update Information:

Update to version 24.13.0

Change Log

* Mon Jan 19 2026 tjuhasz - 1:24.13.0-4 - Replace usage of man_info_compress to be funcional across all branches. * Mon Jan 19 2026 Andrei Radchenko - 1:24.13.0-3 - build: expose libplatform symbols in shared libnode * Fri Jan 16 2026 Fedora Release Engineering - 1:24.13.0-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Tue Jan 13 2026 tjuhasz - 1:24.13.0-1 - Update to version 24.13.0 (rhbz#2421027) * Mon Jan 12 2026 Jan Stan\u011bk - 1:24.11.1-3 - Run version checks only on bundled components * Tue Dec 2 2025 tjuhasz - 1:24.11.1-2 - Fix name collision of the COMPRESS variable in spec file.

References


[ 1 ] Bug #2421027 - nodejs24-24.13.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=2421027 [ 2 ] Bug #2430300 - CVE-2026-22036 nodejs24: Undici has an unbounded decompression chain in HTTP responses on Node.js Fetch API via Content-Encoding leads to resource exhaustion [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2430300 [ 3 ] Bug #2431456 - CVE-2025-55132 nodejs24: Nodejs filesystem permissions bypass [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2431456 [ 4 ] Bug #2431463 - CVE-2026-21637 nodejs24: Nodejs denial of service [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2431463 [ 5 ] Bug #2431470 - CVE-2025-59466 nodejs24: Nodejs denial of service [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2431470 [ 6 ] Bug #2431477 - CVE-2025-59464 nodejs24: Nodejs memory leak [fedora-43] https://bugzilla.redhat.com/show_bug.cgi?id=2431477 [ 7 ] Bug #2431496 - CVE-2025-59465 nodejs2...

Read the Full Advisory

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5cd409edfa' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: nodejs24
Product: Fedora 43
Version: 24.13.0
Release: 4.fc43
Summary: JavaScript runtime

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.