Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
This update includes the following RPMs: nodejs22: * nodejs22-22.23.1-1.hum1 (aarch64, x86_64) * nodejs22-bin-22.23.1-1.hum1 (noarch) * nodejs22-devel-22.23.1-1.hum1 (aarch64, x86_64) * nodejs22-docs-22.23.1-1.hum1 (noarch) * nodejs22-full-i18n-22.23.1-1.hum1 (aarch64, x86_64) * nodejs22-libs-22.23.1-1.hum1 (aarch64, x86_64) * nodejs22-npm-10.9.8-1.22.23.1.1.hum1 (noarch) * nodejs22-npm-bin-22.23.1-1.hum1 (noarch) * v8-12.4-devel-12.4.254.21-1.22.23.1.1.hum1 (aarch64, x86_64) * nodejs22-22.23.1-1.hum1.src (src)
AI Analysis
Technical Summary
This Red Hat security advisory (RHSA-2026:28727) reports on multiple vulnerabilities affecting Red Hat Hardened Images RPMs, including Node.js components. Among the CVEs addressed is CVE-2026-48618, a flaw in Node.js that causes a TLS wildcard-depth authentication bypass due to a mismatch in handling hostnames and unicode dot separators during TLS authentication. This flaw can allow attackers to bypass intended security boundaries, leading to unauthorized access and confidentiality breaches in applications using Node.js for TLS connections. The advisory lists updated RPM packages for nodejs22 and related components but does not confirm that these updates fix all reported CVEs. Red Hat notes that no suitable mitigation or fix currently meets their criteria for ease of use, applicability, or stability. The vulnerability affects Node.js versions 22, 24, and 26 as shipped by Red Hat. The advisory includes references to CWE-209 (Information Exposure), CWE-289 (Authentication Bypass), and CWE-770 (Allocation of Resources Without Limits or Throttling). No CVSS score is provided by Red Hat for these vulnerabilities.
Potential Impact
The primary impact is an authentication bypass vulnerability in Node.js TLS hostname verification, which can allow attackers to circumvent security boundaries and gain unauthorized access to sensitive information. This affects confidentiality but not integrity or availability. The advisory indicates a high severity level due to the potential for unauthorized access and compromise of sensitive data in affected applications. Other vulnerabilities referenced may involve information exposure and resource allocation issues, but specific impacts are not detailed. No known exploits in the wild have been reported.
Mitigation Recommendations
Currently, no official fix or patch is available for the TLS wildcard-depth authentication bypass vulnerability that meets Red Hat's criteria for deployment. Red Hat advises monitoring their advisory pages and applying updates when they become available. Users should refer to the Red Hat Hardened Images update instructions at https://images.redhat.com/ for applying the latest RPM updates. Customers with a Technical Account Manager (TAM) or RHEL Security Select Add-on can consult directly with Red Hat for tailored guidance. No alternative mitigations are provided or recommended by Red Hat at this time.
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
This update includes the following RPMs: nodejs22: * nodejs22-22.23.1-1.hum1 (aarch64, x86_64) * nodejs22-bin-22.23.1-1.hum1 (noarch) * nodejs22-devel-22.23.1-1.hum1 (aarch64, x86_64) * nodejs22-docs-22.23.1-1.hum1 (noarch) * nodejs22-full-i18n-22.23.1-1.hum1 (aarch64, x86_64) * nodejs22-libs-22.23.1-1.hum1 (aarch64, x86_64) * nodejs22-npm-10.9.8-1.22.23.1.1.hum1 (noarch) * nodejs22-npm-bin-22.23.1-1.hum1 (noarch) * v8-12.4-devel-12.4.254.21-1.22.23.1.1.hum1 (aarch64, x86_64) * nodejs22-22.23.1-1.hum1.src (src)
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory (RHSA-2026:28727) reports on multiple vulnerabilities affecting Red Hat Hardened Images RPMs, including Node.js components. Among the CVEs addressed is CVE-2026-48618, a flaw in Node.js that causes a TLS wildcard-depth authentication bypass due to a mismatch in handling hostnames and unicode dot separators during TLS authentication. This flaw can allow attackers to bypass intended security boundaries, leading to unauthorized access and confidentiality breaches in applications using Node.js for TLS connections. The advisory lists updated RPM packages for nodejs22 and related components but does not confirm that these updates fix all reported CVEs. Red Hat notes that no suitable mitigation or fix currently meets their criteria for ease of use, applicability, or stability. The vulnerability affects Node.js versions 22, 24, and 26 as shipped by Red Hat. The advisory includes references to CWE-209 (Information Exposure), CWE-289 (Authentication Bypass), and CWE-770 (Allocation of Resources Without Limits or Throttling). No CVSS score is provided by Red Hat for these vulnerabilities.
Potential Impact
The primary impact is an authentication bypass vulnerability in Node.js TLS hostname verification, which can allow attackers to circumvent security boundaries and gain unauthorized access to sensitive information. This affects confidentiality but not integrity or availability. The advisory indicates a high severity level due to the potential for unauthorized access and compromise of sensitive data in affected applications. Other vulnerabilities referenced may involve information exposure and resource allocation issues, but specific impacts are not detailed. No known exploits in the wild have been reported.
Mitigation Recommendations
Currently, no official fix or patch is available for the TLS wildcard-depth authentication bypass vulnerability that meets Red Hat's criteria for deployment. Red Hat advises monitoring their advisory pages and applying updates when they become available. Users should refer to the Red Hat Hardened Images update instructions at https://images.redhat.com/ for applying the latest RPM updates. Customers with a Technical Account Manager (TAM) or RHEL Security Select Add-on can consult directly with Red Hat for tailored guidance. No alternative mitigations are provided or recommended by Red Hat at this time.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:28727
- Cve Count
- 3
- Additional Cves
- ["CVE-2026-48618","CVE-2026-48933"]
- Cvss Version
- null
Threat ID: 6a42ed1727e9c797199319dd
Added to database: 06/29/2026, 22:09:27 UTC
Last enriched: 08/09/2026, 15:48:12 UTC
Last updated: 08/13/2026, 12:41:10 UTC
Views: 63
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.