ELSA-2026-35842

ELSA-2026-35842 - nodejs22 security, bug fix, and enhancement update

Type:SECURITY
Impact:IMPORTANT
Release Date:2026-07-16

Description


[1:22.23.1-2]
- CVE-2026-42338 ip-address HTML escaping fix.

[1:22.23.1-1]
- Update to version 22.23.1

[1:22.22.2-2]
- De-bundle c-ares, libuv
- we waited for c-ares for about 4 months, so added conditional flag in
case it falls behind in future again, same for libuv


Related CVEs


CVE-2026-11525
CVE-2026-12151
CVE-2026-42338
CVE-2026-48615
CVE-2026-48618
CVE-2026-48619
CVE-2026-48928
CVE-2026-48930
CVE-2026-48933
CVE-2026-48934
CVE-2026-48935
CVE-2026-6733
CVE-2026-9678

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 10 (aarch64) nodejs22-22.23.1-2.el10_2.src.rpmbb62bcbfc479aa717207f9291b22e3d47743bea81bdd05c676191b4fa213f5d9-ol10_aarch64_appstream
nodejs-22.23.1-2.el10_2.aarch64.rpme835f6e9638c71582f1af877313a7f3678800bd457889bfafc52673fd9a59208-ol10_aarch64_appstream
nodejs-devel-22.23.1-2.el10_2.aarch64.rpm689d32cac9407ecdf8470aaa5582185a71fa54659415ff638fc69ebfb52fefc1-ol10_aarch64_appstream
nodejs-docs-22.23.1-2.el10_2.noarch.rpmf73570da7e41c77c8619eefeccc3dfec907b095479ea21153a3cd3ad645f6678-ol10_aarch64_appstream
nodejs-full-i18n-22.23.1-2.el10_2.aarch64.rpm83f93b332dafec193608bf34561ff095efb9fc85d896b425849be49ba32e11f1-ol10_aarch64_appstream
nodejs-libs-22.23.1-2.el10_2.aarch64.rpmdcfd65487f562a9a4432fca7d525f55dae538ac0d02b8c485db63f7611ba587f-ol10_aarch64_appstream
nodejs-npm-10.9.8-1.22.23.1.2.el10_2.aarch64.rpm673deb4cdba61c72fc154b863afd4ed7e27505e9055eb113f704a2995ee8e5ba-ol10_aarch64_appstream
Oracle Linux 10 (x86_64) nodejs22-22.23.1-2.el10_2.src.rpmbb62bcbfc479aa717207f9291b22e3d47743bea81bdd05c676191b4fa213f5d9-ol10_x86_64_appstream
nodejs-22.23.1-2.el10_2.x86_64.rpm07b93776a5c1fa622c252702800f30cafabfe973b936ce8c248c451be4344298-ol10_x86_64_appstream
nodejs-devel-22.23.1-2.el10_2.x86_64.rpm5f2ab02397718082af8ac133571ba043455843fee1a34669fce9ca87c4238cd7-ol10_x86_64_appstream
nodejs-docs-22.23.1-2.el10_2.noarch.rpmf73570da7e41c77c8619eefeccc3dfec907b095479ea21153a3cd3ad645f6678-ol10_x86_64_appstream
nodejs-full-i18n-22.23.1-2.el10_2.x86_64.rpm5d996c4bfef9b4f1386fc2bc826c74064a3e6b5184ecb69a322bc7f98aec4c45-ol10_x86_64_appstream
nodejs-libs-22.23.1-2.el10_2.x86_64.rpm30efcbca19f7a11d92d3fc955553c0529b351d0d17ea2131e6d2f829222740bc-ol10_x86_64_appstream
nodejs-npm-10.9.8-1.22.23.1.2.el10_2.x86_64.rpmb9294943100bc89eb97abfed5beb31ab93d762cc689f87d30b202ac1e546395b-ol10_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete