Fedora 44 nodejs20 Denial of Service Issues Update 2026-05
Node.js is a platform built on Chrome's JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices. Update Information : Update to version 20.20.2 Automatic update for nodejs20-20.20.0-7.fc44.
Node.js is a platform built on Chrome's JavaScript runtime
for easily building fast, scalable network applications.
Node.js uses an event-driven, non-blocking I/O model that
makes it lightweight and efficient, perfect for data-intensive
real-time applications that run across distributed devices.
Update to version 20.20.2 Automatic update for nodejs20-20.20.0-7.fc44.
* Wed Apr 1 2026 tjuhasz - 1:20.20.2-3 - Rework of update of nghttp2 * Mon Mar 30 2026 tjuhasz - 1:20.20.2-2 - Update bundled nghttp2 to 1.68.1 * Wed Mar 25 2026 tjuhasz - 1:20.20.2-1 - Update to version 20.20.2 (rhbz#2444850) * Fri Mar 20 2026 tjuhasz - 1:20.20.1-1 - Update to version 20.20.1 (rhbz#2444850) * Wed Mar 18 2026 Andrei Radchenko - 1:20.20.0-10 - introduce -bins sub-plan * Tue Mar 10 2026 Andrei Radchenko - 1:20.20.0-9 - tests: metadata for all plans * Tue Feb 17 2026 Andrei Radchenko - 1:20.20.0-8 - spec: remove obsolete requires * Tue Feb 17 2026 Jan Stan\u011bk - 1:20.20.0-7 - Disable flaky test on s390x * Mon Feb 16 2026 Jan Stan\u011bk - 1:20.20.0-6 - Own /usr/lib/node_modules again (rhbz#2438837)
* Wed Apr 1 2026 tjuhasz - 1:20.20.2-3 - Rework of update of nghttp2 * Mon Mar 30 2026 tjuhasz - 1:20.20.2-2 - Update bundled nghttp2 to 1.68.1 * Wed Mar 25 2026 tjuhasz - 1:20.20.2-1 - Update to version 20.20.2 (rhbz#2444850) * Fri Mar 20 2026 tjuhasz - 1:20.20.1-1 - Update to version 20.20.1 (rhbz#2444850) * Wed Mar 18 2026 Andrei Radchenko - 1:20.20.0-10 - introduce -bins sub-plan * Tue Mar 10 2026 Andrei Radchenko - 1:20.20.0-9 - tests: metadata for all plans * Tue Feb 17 2026 Andrei Radchenko - 1:20.20.0-8 - spec: remove obsolete requires * Tue Feb 17 2026 Jan Stan\u011bk - 1:20.20.0-7 - Disable flaky test on s390x * Mon Feb 16 2026 Jan Stan\u011bk - 1:20.20.0-6 - Own /usr/lib/node_modules again (rhbz#2438837)
[ 1 ] Bug #2438837 - nodejs20 does not own/provide /usr/lib/node_modules directory [ 2 ] Bug #2453563 - CVE-2026-21717 nodejs20: Node.js: Denial of Service via V8 string hashing mechanism due to predictable hash collisions [fedora-all] [ 3 ] Bug #2453567 - CVE-2026-21714 nodejs20: Node.js: Memory leak and Denial of Service via crafted HTTP/2 WINDOW_UPDATE frames [fedora-all] [ 4 ] Bug #2453570 - CVE-2026-21713 nodejs20: Node.js: Information disclosure via timing oracle in HMAC verification [fedora-all] [ 5 ] Bug #2453592 - CVE-2026-21716 nodejs20: Node.js: Permission bypass allows unauthorized modification of file permissions and ownership via incomplete security fix. [fedora-all] Read the Full Advisory
[ 1 ] Bug #2438837 - nodejs20 does not own/provide /usr/lib/node_modules directory [ 2 ] Bug #2453563 - CVE-2026-21717 nodejs20: Node.js: Denial of Service via V8 string hashing mechanism due to predictable hash collisions [fedora-all] [ 3 ] Bug #2453567 - CVE-2026-21714 nodejs20: Node.js: Memory leak and Denial of Service via crafted HTTP/2 WINDOW_UPDATE frames [fedora-all] [ 4 ] Bug #2453570 - CVE-2026-21713 nodejs20: Node.js: Information disclosure via timing oracle in HMAC verification [fedora-all] [ 5 ] Bug #2453592 - CVE-2026-21716 nodejs20: Node.js: Permission bypass allows unauthorized modification of file permissions and ownership via incomplete security fix. [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c99f9dc3b1' at the command line. For more information, refer to the dnf documentation available at
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-c99f9dc3b1' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
