Critical Node.js Vulnerabilities Affecting Rocky Linux Versions

Critical Node.js Vulnerabilities Affecting Rocky Linux Versions

First seen 2 Sep 2026, 13:13 UTC Linuxsecurity 58.5

Article Content

Browse articles
ThreatCluster

Recent updates have revealed critical vulnerabilities in Node.js affecting Rocky Linux 8 and 9. The vulnerabilities include a critical permission issue and a denial of service vulnerability, with specific CVEs yet to be disclosed. The updates impact various Node.js modules, including nodejs, nodejs-packaging, and nodejs-nodemon. The CVSS base score for these vulnerabilities indicates a high severity level. Administrators are urged to apply the patches immediately to mitigate potential exploitation risks. The vulnerabilities could allow unauthorized access and denial of service, affecting a wide range of applications relying on Node.js. The advisory emphasizes the importance of maintaining updated systems to prevent security breaches. Current status indicates that patches are available for both Rocky Linux 8 and 9.

Key Points: • Critical vulnerabilities in Node.js affect Rocky Linux 8 and 9. • Patches are available; immediate application is recommended. • Vulnerabilities may lead to unauthorized access and denial of service.

Timeline

2026-08-31
Critical permission issue disclosed
An advisory was published detailing a critical permission issue in Node.js affecting Rocky Linux 9.
Linuxsecurity
2026-09-02
Denial of service vulnerability disclosed
An advisory was published regarding an important denial of service vulnerability in Node.js affecting Rocky Linux 8.
Linuxsecurity
2026-09-02
Patches released for both versions
Updates were released for Node.js modules to address the vulnerabilities in Rocky Linux 8 and 9.
Linuxsecurity