Skip to main content
EPSS 1.7%top 24%

A flaw in Node.js’s Permissions model allows attackers to bypass --allow-fs-read and --allow-fs-write restrictions using crafted relative symlink… (CVE-2025-55130)

0
Critical
Published: 01/26/2026 (01/26/2026, 14:47:49 UTC)
Source: GCVE Database
Product: node

Description

A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and read sensitive files. This breaks the expected isolation guarantees and enables arbitrary file read/write, leading to potential system compromise. This vulnerability affects users of the permission model on Node.js v20, v22, v24, and v25.

Affected software

Affected versions
Red HatRed Hat Hardened Imagesaarch64nodejs24-main@aarch64nodejs20-main@aarch64nodejs25-main@aarch64nodejs22-main@aarch64>=20.0.0 <20.20.0>=21.0.0 <22.22.0>=23.0.0 <24.13.0>=25.0.0 <25.3.0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/16/2026, 18:06:12 UTC

Technical Analysis

The advisory covers a set of security issues affecting Red Hat Hardened Images RPMs, particularly Node.js 20 packages. One highlighted vulnerability (CVE-2025-59464) involves a memory leak in Node.js's OpenSSL integration when converting X.509 certificate fields to UTF-8, causing memory to be allocated without being freed. This can be exploited remotely via repeated TLS connections to cause resource exhaustion and denial of service. The advisory lists multiple CVEs and CWE categories related to resource allocation, authentication, and information exposure. The update includes new RPM versions for nodejs20 and related components. However, the vendor advisory does not explicitly state that a fix for CVE-2025-59464 or other CVEs is currently available or deployed, and mitigation options for this specific memory leak are noted as unavailable or insufficient per Red Hat criteria.

Potential Impact

The primary impact is denial of service through resource exhaustion caused by a memory leak in Node.js's OpenSSL integration. Remote attackers can trigger steady memory growth by repeatedly establishing TLS connections, potentially leading to application or system instability. Other listed CVEs and CWEs suggest additional security concerns related to authentication bypass, information exposure, and resource management, but detailed impact descriptions are limited. No known exploits in the wild have been reported.

Mitigation Recommendations

The vendor advisory indicates that mitigation for the Node.js memory leak (CVE-2025-59464) is either not available or does not meet Red Hat's criteria for deployment. No explicit patch availability is confirmed in the advisory text. Users should monitor Red Hat's official errata and update channels for forthcoming fixes. Until a fix is released, consider limiting exposure of affected services to untrusted networks or applying any vendor-recommended workarounds if provided in future advisories.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:2781
Cve Count
6
Additional Cves
["CVE-2025-55131","CVE-2025-55132","CVE-2025-59465","CVE-2025-59466","CVE-2026-21637"]
Cvss Version
3.0
State
PUBLISHED

Threat ID: 6a27e99f8dd33fbd8516d255

Added to database: 06/09/2026, 10:23:27 UTC

Last enriched: 08/16/2026, 18:06:12 UTC

Last updated: 09/13/2026, 22:01:30 UTC

Views: 112

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

External Links

NVD DatabaseMITRE CVEhttps://access.redhat.com/errata/RHSA-2026:7378https://images.redhat.com/https://access.redhat.com/security/cve/CVE-2025-59464https://access.redhat.com/security/updates/classification/https://access.redhat.com/security/cve/CVE-2025-55132https://access.redhat.com/security/cve/CVE-2025-55131https://access.redhat.com/security/cve/CVE-2025-55130https://access.redhat.com/security/cve/CVE-2026-2950https://access.redhat.com/security/cve/CVE-2026-45149https://access.redhat.com/security/cve/CVE-2026-9697https://access.redhat.com/security/cve/CVE-2026-6734https://access.redhat.com/security/cve/CVE-2026-9675https://access.redhat.com/security/cve/CVE-2026-9678https://access.redhat.com/security/cve/CVE-2026-48618https://access.redhat.com/security/cve/CVE-2026-48933https://access.redhat.com/security/cve/CVE-2026-48615https://access.redhat.com/security/cve/CVE-2026-48936https://access.redhat.com/security/cve/CVE-2026-48934https://access.redhat.com/security/cve/CVE-2026-48928https://access.redhat.com/security/cve/CVE-2026-48930https://access.redhat.com/errata/RHSA-2026:6431https://access.redhat.com/security/cve/CVE-2026-21637https://access.redhat.com/security/cve/CVE-2026-21636https://access.redhat.com/security/cve/CVE-2025-59466https://access.redhat.com/security/cve/CVE-2025-59465https://access.redhat.com/security/cve/CVE-2026-21717https://access.redhat.com/security/cve/CVE-2026-21716Canonical URLhttps://access.redhat.com/errata/RHSA-2026:6402Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7386Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7387Canonical URLhttps://access.redhat.com/errata/RHSA-2026:7657Canonical URLReference 37Reference 38Reference 39Reference 40Reference 41Reference 42Reference 43Reference 44Reference 45Reference 46Reference 47Reference 48Reference 49Reference 50Reference 51Search on Google

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses