elsa-2026-35842
oracle_linux
Description
[1:22.23.1-2] - CVE-2026-42338 ip-address HTML escaping fix. [1:22.23.1-1] - Update to version 22.23.1 [1:22.22.2-2] - De-bundle c-ares, libuv - we waited for c-ares for about 4 months, so added conditional flag in case it falls behind in future again, same for libuv
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cves": [
"CVE-2026-11525",
"CVE-2026-12151",
"CVE-2026-42338",
"CVE-2026-48615",
"CVE-2026-48618",
"CVE-2026-48619",
"CVE-2026-48928",
"CVE-2026-48930",
"CVE-2026-48933",
"CVE-2026-48934",
"CVE-2026-48935",
"CVE-2026-6733",
"CVE-2026-9678"
],
"cvss": 0.0,
"database_specific": {
"severity": "IMPORTANT"
},
"description": "[1:22.23.1-2]\n- CVE-2026-42338 ip-address HTML escaping fix.\n\n[1:22.23.1-1]\n- Update to version 22.23.1\n\n[1:22.22.2-2]\n- De-bundle c-ares, libuv\n- we waited for c-ares for about 4 months, so added conditional flag in\n case it falls behind in future again, same for libuv",
"id": "ELSA-2026-35842",
"ovalId": "oval:com.oracle.elsa:def:202635842",
"source": "oracle_linux",
"title": "ELSA-2026-35842: nodejs22 security, bug fix, and enhancement update (IMPORTANT)",
"url": "https://linux.oracle.com/errata/ELSA-2026-35842.html"
}