Multiple Node.js Security Vulnerabilities in Oracle Linux 9 and 10

Multiple Node.js Security Vulnerabilities in Oracle Linux 9 and 10

First seen 3 Sep 2026, 07:00 UTC Linuxsecurity 57.9

Article Content

Browse articles
ThreatCluster

Oracle has released multiple security advisories for Node.js vulnerabilities affecting Oracle Linux 9 and 10. The advisories include ELSA-2026-61383 and ELSA-2026-61386 for Oracle Linux 9, addressing CVEs such as CVE-2026-56846, CVE-2026-56848, and CVE-2026-69152. The vulnerabilities could potentially allow for remote code execution and denial of service attacks. Oracle Linux 10 also received an update (ELSA-2026-61376) that addresses similar vulnerabilities with Node.js version 22.23.2. Administrators are urged to apply the patches immediately to mitigate risks. The updates include important fixes and enhancements to the Node.js packages and their dependencies. The advisories emphasize the importance of maintaining up-to-date systems to prevent exploitation. As of now, there are no confirmed reports of active exploitation for these vulnerabilities.

Key Points: • Oracle Linux 9 and 10 have critical Node.js vulnerabilities requiring immediate patching. • CVE-2026-69152 and others could lead to remote code execution and denial of service. • Patches for Node.js versions 22.23.2 and 24.19.0 are now available.

Timeline

2026-07-30
CVE-2026-58043 published
CVE-2026-58043 was published, detailing another significant vulnerability in Node.js.
Linuxsecurity
2026-08-03
CVE-2026-69152 published
CVE-2026-69152 was published, highlighting a critical vulnerability in Node.js.
Linuxsecurity
2026-08-04
CVE-2026-56846 and CVE-2026-56848 published
CVE-2026-56846 and CVE-2026-56848 were published, both affecting Node.js security.
Linuxsecurity
2026-09-02
Oracle Linux 10 Node.js update released
Oracle released ELSA-2026-61376 for Oracle Linux 10, addressing Node.js vulnerabilities.
Linuxsecurity
2026-09-03
Oracle Linux 9 Node.js updates released
Oracle released ELSA-2026-61383 and ELSA-2026-61386 for Oracle Linux 9, addressing critical vulnerabilities.
Linuxsecurity