Important: nodejs:22 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:2782", "synopsis": "Important: nodejs:22 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for nodejs-packaging, module.nodejs-nodemon, module.nodejs-packaging, nodejs-nodemon.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. \n\nSecurity Fix(es):\n\n* nodejs: Nodejs filesystem permissions bypass (CVE-2025-55132)\n\n* nodejs: Nodejs denial of service (CVE-2026-21637)\n\n* nodejs: Nodejs denial of service (CVE-2025-59466)\n\n* nodejs: Nodejs denial of service (CVE-2025-59465)\n\n* nodejs: Nodejs uninitialized memory exposure (CVE-2025-55131)\n\n* nodejs: Nodejs file permissions bypass (CVE-2025-55130)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2431338", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431338", "description": ""}, {"ticket": "2431340", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431340", "description": ""}, {"ticket": "2431343", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431343", "description": ""}, {"ticket": "2431349", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431349", "description": ""}, {"ticket": "2431350", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431350", "description": ""}, {"ticket": "2431352", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2431352", "description": ""}], "cves": [{"name": "CVE-2025-55130", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-55130", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.1", "cwe": "CWE-281"}, {"name": "CVE-2025-55131", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-55131", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L", "cvss3BaseScore": "7.1", "cwe": "CWE-497"}, {"name": "CVE-2025-55132", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-55132", "cvss3ScoringVector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N", "cvss3BaseScore": "2.8", "cwe": "CWE-281"}, {"name": "CVE-2025-59465", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-59465", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-248"}, {"name": "CVE-2025-59466", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-59466", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-770"}, {"name": "CVE-2026-21637", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-21637", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-248"}], "references": [], "publishedAt": "2026-02-18T09:05:30.043251Z", "rpms": {"Rocky Linux 9": {"nvras": ["nodejs-nodemon-0:3.0.1-1.module+el9.7.0+40017+f0db1785.noarch.rpm", "nodejs-nodemon-0:3.0.1-1.module+el9.7.0+40018+a011993d.noarch.rpm", "nodejs-nodemon-0:3.0.1-1.module+el9.7.0+40022+9ecc286c.noarch.rpm", "nodejs-nodemon-0:3.0.1-1.module+el9.7.0+40017+f0db1785.src.rpm", "nodejs-nodemon-0:3.0.1-1.module+el9.7.0+40022+9ecc286c.src.rpm", "nodejs-nodemon-0:3.0.1-1.module+el9.7.0+40018+a011993d.src.rpm", "nodejs-packaging-0:2021.06-5.module+el9.7.0+40051+f2ef3f49.noarch.rpm","nodejs-packaging-0:2021.06-5.module+el9.7.0+40050+22a42328.noarch.rpm", "nodejs-packaging-0:2021.06-5.module+el9.7.0+40050+22a42328.src.rpm", "nodejs-packaging-0:2021.06-5.module+el9.7.0+40051+f2ef3f49.src.rpm", "nodejs-packaging-bundler-0:2021.06-5.module+el9.7.0+40051+f2ef3f49.noarch.rpm", "nodejs-packaging-bundler-0:2021.06-5.module+el9.7.0+40050+22a42328.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. Update for Node.js on Rocky Linux 9 addresses important security issues including filesystem bypass and DoS vulnerabilities.. Rocky Linux Node.js security important update. . Severity: Important. LinuxSecurity.com Team
Important: nodejs:24 security update. {"type": "TYPE_SECURITY", "shortCode": "RL", "name": "RLSA-2026:2781", "synopsis": "Important: nodejs:24 security update", "severity": "SEVERITY_IMPORTANT", "topic": "An update is available for nodejs-packaging, module.nodejs-nodemon, module.nodejs-packaging, nodejs-nodemon.\nThis update affects Rocky Linux 9.\nA Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list", "description": "Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. \n\nSecurity Fix(es):\n\n* nodejs: Nodejs filesystem permissions bypass (CVE-2025-55132)\n\n* nodejs: Nodejs denial of service (CVE-2026-21637)\n\n* nodejs: Nodejs denial of service (CVE-2025-59466)\n\n* nodejs: Nodejs denial of service (CVE-2025-59465)\n\n* nodejs: Nodejs uninitialized memory exposure (CVE-2025-55131)\n\n* nodejs: Nodejs file permissions bypass (CVE-2025-55130)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "solution": null, "affectedProducts": ["Rocky Linux 9"], "fixes": [{"ticket": "2431338", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431338", "description": ""}, {"ticket": "2431340", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431340", "description": ""}, {"ticket": "2431343", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431343", "description": ""}, {"ticket": "2431349", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431349", "description": ""}, {"ticket": "2431350", "sourceBy": "Red Hat", "sourceLink": "https://bugzilla.redhat.com/show_bug.cgi?id=2431350", "description": ""}, {"ticket": "2431352", "sourceBy": "Red Hat", "sourceLink":"https://bugzilla.redhat.com/show_bug.cgi?id=2431352", "description": ""}], "cves": [{"name": "CVE-2025-55130", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-55130", "cvss3ScoringVector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N", "cvss3BaseScore": "7.1", "cwe": "CWE-281"}, {"name": "CVE-2025-55131", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-55131", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L", "cvss3BaseScore": "7.1", "cwe": "CWE-497"}, {"name": "CVE-2025-55132", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-55132", "cvss3ScoringVector": "CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N", "cvss3BaseScore": "2.8", "cwe": "CWE-281"}, {"name": "CVE-2025-59465", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-59465", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "7.5", "cwe": "CWE-248"}, {"name": "CVE-2025-59466", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2025-59466", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-770"}, {"name": "CVE-2026-21637", "sourceBy": "MITRE", "sourceLink": "https://www.cve.org/CVERecord?id=CVE-2026-21637", "cvss3ScoringVector": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H", "cvss3BaseScore": "5.9", "cwe": "CWE-248"}], "references": [], "publishedAt": "2026-02-18T09:05:30.043251Z", "rpms": {"Rocky Linux 9": {"nvras": ["nodejs-nodemon-0:3.0.3-3.module+el9.7.0+40025+0e0cf6b2.noarch.rpm", "nodejs-nodemon-0:3.0.3-3.module+el9.7.0+40025+0e0cf6b2.src.rpm", "nodejs-packaging-0:2021.06-6.module+el9.7.0+40052+e32ea525.noarch.rpm", "nodejs-packaging-0:2021.06-6.module+el9.7.0+40052+e32ea525.src.rpm", "nodejs-packaging-bundler-0:2021.06-6.module+el9.7.0+40052+e32ea525.noarch.rpm"]}}, "rebootSuggested": false, "buildReferences": []}. A critical nodejs update for Rocky Linux 9 addresses multiple important securityissues to enhance system protection.. nodejs update, rocky linux, security advisory, important fixes, system security. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.