Skip to main content
EPSS 0.5%top 56%

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

0
High
Published: 07/10/2026 (07/10/2026, 03:35:32 UTC)
Source: GCVE Database
Vendor/Project: Red Hat Product Security
Product: Red Hat

Description

This update includes the following RPMs: nodejs26: * nodejs26-26.4.0-1.4.hum1 (aarch64, x86_64) * nodejs26-bin-26.4.0-1.4.hum1 (noarch) * nodejs26-devel-26.4.0-1.4.hum1 (aarch64, x86_64) * nodejs26-docs-26.4.0-1.4.hum1 (noarch) * nodejs26-full-i18n-26.4.0-1.4.hum1 (aarch64, x86_64) * nodejs26-libs-26.4.0-1.4.hum1 (aarch64, x86_64) * nodejs26-npm-11.17.0-1.26.4.0.1.4.hum1 (noarch) * nodejs26-npm-bin-26.4.0-1.4.hum1 (noarch) * v8-14.6-devel-14.6.202.34-1.26.4.0.1.4.hum1 (aarch64, x86_64) * nodejs26-26.4.0-1.4.hum1.src (src) Security Fix(es): nodejs26: * CVE-2026-59869

Affected software

Affected versions
>=4.22=4.3.1.3-r5Red HatRed Hat Hardened Imagesaarch64nodejs26-main@aarch64nodejs22-main@aarch64Red Hat Container Native VirtualizationRed Hat Container Native Virtualization 4.22amd64registry.redhat.io/container-native-virtualization/kubevirt-console-plugin-rhel9@sha256:5d71337ae41180ff3c836ea11db86203414c2220f1a55d5c1aec145d0c6d4310_amd64Red Hat OpenShift Service MeshRed Hat OpenShift Service Mesh 3.2registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:9cd865290c175e0d49596f1995ea071ac9531205bf54799e67c5840154cb23a9_amd64Red Hat OpenShift Service Mesh 3.0registry.redhat.io/openshift-service-mesh/kiali-rhel9@sha256:b672cd8391ff79a4b9be089d2a908bf51076d0a8f2345973d298ee4c53228992_amd64

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 08/15/2026, 00:19:04 UTC

Technical Analysis

CVE-2026-59869 is a denial of service vulnerability in the js-yaml JavaScript YAML parser and dumper. The flaw allows a remote attacker to provide a crafted YAML document containing a chain of mappings with merge keys, which causes the parser to consume excessive CPU resources. This leads to a denial of service condition on affected systems. Red Hat products that utilize js-yaml to process untrusted YAML input, including Thingsboard versions prior to 4.3.1.3-r4 and Red Hat Hardened Images with nodejs26 packages, are affected. The vulnerability is rated Important by Red Hat and has a CVSS v3 base score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). A patch is available in Thingsboard 4.3.1.3-r4 and corresponding updated Red Hat packages. Mitigation involves restricting processing of untrusted YAML documents, implementing input validation and sanitization, and limiting network access to YAML parsing services.

Potential Impact

The vulnerability allows remote attackers to cause a denial of service by consuming excessive CPU resources when processing specially crafted YAML documents. This can disrupt availability of affected applications and services without requiring authentication or complex attack vectors. No confidentiality or integrity impacts are reported.

Mitigation Recommendations

A patch is available in Thingsboard version 4.3.1.3-r4 and updated Red Hat Hardened Images packages (e.g., nodejs26-26.4.0-1.4.hum1). Users should apply these updates to remediate the vulnerability. Additionally, restrict processing of untrusted YAML input by applications relying on js-yaml, implement robust input validation and sanitization for YAML data from untrusted sources, and consider limiting network access to YAML parsing services to trusted clients via firewall rules.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:38304
Cve Count
1
State
PUBLISHED

Threat ID: 6a5c47772a4a8d5989eb4ff8

Added to database: 07/19/2026, 03:41:43 UTC

Last enriched: 08/15/2026, 00:19:04 UTC

Last updated: 09/11/2026, 22:08:24 UTC

Views: 119

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses