elsa-2026-7302

oracle_linux
Description

nodejs [1:22.22.2-1] - Update to version 22.22.2 - introduced patch updating deps/nghttp2 to v 1.68.1 for CVE-2026-27135 - disabled failing tests in nghttp2 due to newer version - patch for npm/braces CVE-2026-25547 Resolves: RHEL-163369 Fixes: CVE-2026-1528 CVE-2026-2229 CVE-2026-1526 CVE-2026-1525 CVE-2026-27135 CVE-2026-27904 CVE-2026-26996 CVE-2026-25547 nodejs-nodemon [3.0.1-1] - Rebase to 3.0.1 - Resolves: CVE-2022-25883 [2.0.20-2] - Patch bundled glob-parent - Resolves: CVE-2021-35065 [2.0.20-1] - Rebase to 2.0.20 Resolves: CVE-2022-3517 [2.0.15-1] - Resolves: RHBZ#2005419 - Resolves CVE-2020-28469 - Rebase to newest version - Change source to npmjs.com nodejs-packaging [2021.06-6] - Properly handle @group/package deps in nodejs-symlink-deps Resolves: RHEL-121582 [2021.06-5] - nodejs.req to properly detect bundled deps

Timeline
Published
unknown
Last Modified
unknown
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "cves": [
    "CVE-2026-1525",
    "CVE-2026-1526",
    "CVE-2026-1528",
    "CVE-2026-21710",
    "CVE-2026-2229",
    "CVE-2026-25547",
    "CVE-2026-26996",
    "CVE-2026-27135",
    "CVE-2026-27904"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "nodejs\n[1:22.22.2-1]\n- Update to version 22.22.2\n- introduced patch updating deps/nghttp2 to v 1.68.1 for CVE-2026-27135\n- disabled failing tests in nghttp2 due to newer version\n- patch for npm/braces CVE-2026-25547\n  Resolves: RHEL-163369\n  Fixes: CVE-2026-1528 CVE-2026-2229 CVE-2026-1526 CVE-2026-1525 CVE-2026-27135 CVE-2026-27904 CVE-2026-26996 CVE-2026-25547\n\nnodejs-nodemon\n[3.0.1-1]\n- Rebase to 3.0.1\n- Resolves: CVE-2022-25883\n\n[2.0.20-2]\n- Patch bundled glob-parent\n- Resolves: CVE-2021-35065\n\n[2.0.20-1]\n- Rebase to 2.0.20\n  Resolves: CVE-2022-3517\n\n[2.0.15-1]\n- Resolves: RHBZ#2005419\n- Resolves CVE-2020-28469\n- Rebase to newest version\n- Change source to npmjs.com\n\nnodejs-packaging\n[2021.06-6]\n- Properly handle @group/package deps in nodejs-symlink-deps\n  Resolves: RHEL-121582\n\n[2021.06-5]\n- nodejs.req to properly detect bundled deps",
  "id": "ELSA-2026-7302",
  "ovalId": "oval:com.oracle.elsa:def:20267302",
  "source": "oracle_linux",
  "title": "ELSA-2026-7302:  nodejs:22 security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2026-7302.html"
}
View JSON API Download JSON