{"cves":["CVE-2026-11525","CVE-2026-12151","CVE-2026-42338","CVE-2026-48615","CVE-2026-48618","CVE-2026-48619","CVE-2026-48928","CVE-2026-48930","CVE-2026-48933","CVE-2026-48934","CVE-2026-48935","CVE-2026-6733","CVE-2026-9678"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[1:22.23.1-2]\n- CVE-2026-42338 ip-address HTML escaping fix.\n\n[1:22.23.1-1]\n- Update to version 22.23.1\n\n[1:22.22.2-2]\n- De-bundle c-ares, libuv\n- we waited for c-ares for about 4 months, so added conditional flag in\n  case it falls behind in future again, same for libuv","id":"ELSA-2026-35842","ovalId":"oval:com.oracle.elsa:def:202635842","source":"oracle_linux","title":"ELSA-2026-35842:  nodejs22 security, bug fix, and enhancement update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-35842.html"}