Fedora 43 Nodejs20 Important Denial of Service Issues 2026
Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices. Update Information : Update to version 20.20.2
Node.js is a platform built on Chrome's JavaScript runtime
for easily building fast, scalable network applications.
Node.js uses an event-driven, non-blocking I/O model that
makes it lightweight and efficient, perfect for data-intensive
real-time applications that run across distributed devices.
Update to version 20.20.2
* Tue Apr 14 2026 tjuhasz - 1:20.20.2-3 - Rework of update of nghttp2 * Tue Apr 14 2026 tjuhasz - 1:20.20.2-2 - Update bundled nghttp2 to 1.68.1 * Tue Apr 14 2026 tjuhasz - 1:20.20.2-1 - Update to version 20.20.2 (rhbz#2444850) * Tue Apr 14 2026 tjuhasz - 1:20.20.1-1 - Update to version 20.20.1 (rhbz#2444850) * Tue Apr 14 2026 Jan Stan\u011bk - 1:20.20.0-5 - Disable flaky test on s390x * Tue Apr 14 2026 Jan Stan\u011bk - 1:20.20.0-4 - Own /usr/lib/node_modules again (rhbz#2438837) * Tue Apr 14 2026 Jan Stan\u011bk - 1:20.20.0-3 - Convert to -gen packaging - Use packaging scripts and spec file structure from current nodejs24
* Tue Apr 14 2026 tjuhasz - 1:20.20.2-3 - Rework of update of nghttp2 * Tue Apr 14 2026 tjuhasz - 1:20.20.2-2 - Update bundled nghttp2 to 1.68.1 * Tue Apr 14 2026 tjuhasz - 1:20.20.2-1 - Update to version 20.20.2 (rhbz#2444850) * Tue Apr 14 2026 tjuhasz - 1:20.20.1-1 - Update to version 20.20.1 (rhbz#2444850) * Tue Apr 14 2026 Jan Stan\u011bk - 1:20.20.0-5 - Disable flaky test on s390x * Tue Apr 14 2026 Jan Stan\u011bk - 1:20.20.0-4 - Own /usr/lib/node_modules again (rhbz#2438837) * Tue Apr 14 2026 Jan Stan\u011bk - 1:20.20.0-3 - Convert to -gen packaging - Use packaging scripts and spec file structure from current nodejs24
[ 1 ] Bug #2447158 - CVE-2026-1528 nodejs20: undici: Denial of Service via crafted WebSocket frame with large length [fedora-all] [ 2 ] Bug #2447161 - CVE-2026-2229 nodejs20: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter [fedora-all] [ 3 ] Bug #2447168 - CVE-2026-1525 nodejs20: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers [fedora-all] [ 4 ] Bug #2447172 - CVE-2026-1527 nodejs20: Undici: HTTP header injection and request smuggling vulnerability [fedora-all] [ 5 ] Bug #2447179 - CVE-2026-1526 nodejs20: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression [fedora-all] Read the Full Advisory
[ 1 ] Bug #2447158 - CVE-2026-1528 nodejs20: undici: Denial of Service via crafted WebSocket frame with large length [fedora-all] [ 2 ] Bug #2447161 - CVE-2026-2229 nodejs20: Undici: Denial of Service via invalid WebSocket permessage-deflate extension parameter [fedora-all] [ 3 ] Bug #2447168 - CVE-2026-1525 nodejs20: Undici: HTTP Request Smuggling and Denial of Service due to duplicate Content-Length headers [fedora-all] [ 4 ] Bug #2447172 - CVE-2026-1527 nodejs20: Undici: HTTP header injection and request smuggling vulnerability [fedora-all] [ 5 ] Bug #2447179 - CVE-2026-1526 nodejs20: undici: Denial of Service via unbounded memory consumption during WebSocket permessage-deflate decompression [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9dc3a61ad8' at the command line. For more information, refer to the dnf documentation available at
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-9dc3a61ad8' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
