Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
This update includes the following RPMs: nodejs26: * nodejs26-26.4.0-1.4.hum1 (aarch64, x86_64) * nodejs26-bin-26.4.0-1.4.hum1 (noarch) * nodejs26-devel-26.4.0-1.4.hum1 (aarch64, x86_64) * nodejs26-docs-26.4.0-1.4.hum1 (noarch) * nodejs26-full-i18n-26.4.0-1.4.hum1 (aarch64, x86_64) * nodejs26-libs-26.4.0-1.4.hum1 (aarch64, x86_64) * nodejs26-npm-11.17.0-1.26.4.0.1.4.hum1 (noarch) * nodejs26-npm-bin-26.4.0-1.4.hum1 (noarch) * v8-14.6-devel-14.6.202.34-1.26.4.0.1.4.hum1 (aarch64, x86_64) * nodejs26-26.4.0-1.4.hum1.src (src) Security Fix(es): nodejs26: * CVE-2026-59869
AI Analysis
Technical Summary
CVE-2026-59869 is a denial of service vulnerability in the js-yaml JavaScript YAML parser and dumper. The flaw allows a remote attacker to provide a crafted YAML document containing a chain of mappings with merge keys, which causes the parser to consume excessive CPU resources. This leads to a denial of service condition on affected systems. Red Hat products that utilize js-yaml to process untrusted YAML input, including Thingsboard versions prior to 4.3.1.3-r4 and Red Hat Hardened Images with nodejs26 packages, are affected. The vulnerability is rated Important by Red Hat and has a CVSS v3 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). A patch is available in Thingsboard 4.3.1.3-r4 and corresponding updated Red Hat packages. Mitigation involves restricting processing of untrusted YAML documents, implementing input validation and sanitization, and limiting network access to YAML parsing services.
Potential Impact
The vulnerability allows remote attackers to cause a denial of service by consuming excessive CPU resources when processing specially crafted YAML documents. This can disrupt availability of affected applications and services without requiring authentication or complex attack vectors. No confidentiality or integrity impacts are reported.
Mitigation Recommendations
A patch is available in Thingsboard version 4.3.1.3-r4 and updated Red Hat Hardened Images packages (e.g., nodejs26-26.4.0-1.4.hum1). Users should apply these updates to remediate the vulnerability. Additionally, restrict processing of untrusted YAML input by applications relying on js-yaml, implement robust input validation and sanitization for YAML data from untrusted sources, and consider limiting network access to YAML parsing services to trusted clients via firewall rules.
Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update
Description
This update includes the following RPMs: nodejs26: * nodejs26-26.4.0-1.4.hum1 (aarch64, x86_64) * nodejs26-bin-26.4.0-1.4.hum1 (noarch) * nodejs26-devel-26.4.0-1.4.hum1 (aarch64, x86_64) * nodejs26-docs-26.4.0-1.4.hum1 (noarch) * nodejs26-full-i18n-26.4.0-1.4.hum1 (aarch64, x86_64) * nodejs26-libs-26.4.0-1.4.hum1 (aarch64, x86_64) * nodejs26-npm-11.17.0-1.26.4.0.1.4.hum1 (noarch) * nodejs26-npm-bin-26.4.0-1.4.hum1 (noarch) * v8-14.6-devel-14.6.202.34-1.26.4.0.1.4.hum1 (aarch64, x86_64) * nodejs26-26.4.0-1.4.hum1.src (src) Security Fix(es): nodejs26: * CVE-2026-59869
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-59869 is a denial of service vulnerability in the js-yaml JavaScript YAML parser and dumper. The flaw allows a remote attacker to provide a crafted YAML document containing a chain of mappings with merge keys, which causes the parser to consume excessive CPU resources. This leads to a denial of service condition on affected systems. Red Hat products that utilize js-yaml to process untrusted YAML input, including Thingsboard versions prior to 4.3.1.3-r4 and Red Hat Hardened Images with nodejs26 packages, are affected. The vulnerability is rated Important by Red Hat and has a CVSS v3 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). A patch is available in Thingsboard 4.3.1.3-r4 and corresponding updated Red Hat packages. Mitigation involves restricting processing of untrusted YAML documents, implementing input validation and sanitization, and limiting network access to YAML parsing services.
Potential Impact
The vulnerability allows remote attackers to cause a denial of service by consuming excessive CPU resources when processing specially crafted YAML documents. This can disrupt availability of affected applications and services without requiring authentication or complex attack vectors. No confidentiality or integrity impacts are reported.
Mitigation Recommendations
A patch is available in Thingsboard version 4.3.1.3-r4 and updated Red Hat Hardened Images packages (e.g., nodejs26-26.4.0-1.4.hum1). Users should apply these updates to remediate the vulnerability. Additionally, restrict processing of untrusted YAML input by applications relying on js-yaml, implement robust input validation and sanitization for YAML data from untrusted sources, and consider limiting network access to YAML parsing services to trusted clients via firewall rules.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:38304
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6a5c47772a4a8d5989eb4ff8
Added to database: 07/19/2026, 03:41:43 UTC
Last enriched: 08/15/2026, 00:19:04 UTC
Last updated: 09/11/2026, 22:08:24 UTC
Views: 119
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.