{"cves":["CVE-2026-1525","CVE-2026-1526","CVE-2026-1528","CVE-2026-21710","CVE-2026-2229","CVE-2026-25547","CVE-2026-26996","CVE-2026-27135","CVE-2026-27904"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[1:22.22.2-1]\n- Update to version 22.22.2\n- introduced patch updating deps/nghttp2 to v 1.68.1 for CVE-2026-27135\n- disabled failing tests in nghttp2 due to newer version\n- patch for npm/braces CVE-2026-25547\n\n[1:22.22.0-4]\n- sources: changed ICU version syntax","id":"ELSA-2026-7080","ovalId":"oval:com.oracle.elsa:def:20267080","source":"oracle_linux","title":"ELSA-2026-7080:  nodejs22 security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2026-7080.html"}