Red Hat Security Advisory: nodejs:22 security update
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data (CVE-2026-11822) * sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 (CVE-2026-11824) * brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257) * ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification (CVE-2026-54272) * nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw (CVE-2026-58043) * brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152) * ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192) * nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks (CVE-2026-56846) * nodejs: Node.js: Heap-use-after-free in HTTP/2 handling can lead to denial of service (CVE-2026-56848) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
AI Analysis
Technical Summary
This vulnerability involves memory corruption in the FTS5 extension of SQLite prior to version 3.53.2. The FTS5 extension is used for full-text search capabilities within SQLite. Memory corruption vulnerabilities can potentially lead to crashes or arbitrary code execution, but no specific exploitation details or impact scenarios are provided in the available information. The vulnerability is tracked as CVE-2026-11822 and is referenced by Microsoft Security Response Center. The affected versions include SQLite versions before 3.53.2, though the input data only explicitly mentions version =3.0 and Azure Linux 3.0 without clear version range. No patch or fix details are provided.
Potential Impact
The vulnerability is a memory corruption issue (CWE-122) in SQLite's FTS5 extension, which could lead to instability or potential security risks such as code execution if exploited. However, no confirmed exploitation in the wild is reported, and no detailed impact analysis is available from the provided data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor Microsoft Security Response Center advisories for updates. No specific mitigation steps are provided in the available data.
Red Hat Security Advisory: nodejs:22 security update
Description
Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language. Security Fix(es): * sqlite: SQLite: Arbitrary code execution via crafted FTS5 full-text search data (CVE-2026-11822) * sqlite: SQLite: Arbitrary code execution and crash via heap-based buffer overflow in FTS5 (CVE-2026-11824) * brace-expansion: Brace-expansion: Denial of Service via memory exhaustion in expand() function (CVE-2026-14257) * ip-address: ip-address: Server-Side Request Forgery via IPv4-mapped/NAT64 IPv6 address misclassification (CVE-2026-54272) * nodejs: Node.js: Unauthorized filesystem access due to Permission Model enforcement flaw (CVE-2026-58043) * brace-expansion: DoS via unbounded intermediate arrays, bypassing the CVE-2026-14257 mitigation (CVE-2026-69152) * ip-address: ip-address: Inconsistent IP address parsing leads to Server-Side Request Forgery (SSRF) and trust-boundary bypass (CVE-2026-69192) * nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks (CVE-2026-56846) * nodejs: Node.js: Heap-use-after-free in HTTP/2 handling can lead to denial of service (CVE-2026-56848) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability involves memory corruption in the FTS5 extension of SQLite prior to version 3.53.2. The FTS5 extension is used for full-text search capabilities within SQLite. Memory corruption vulnerabilities can potentially lead to crashes or arbitrary code execution, but no specific exploitation details or impact scenarios are provided in the available information. The vulnerability is tracked as CVE-2026-11822 and is referenced by Microsoft Security Response Center. The affected versions include SQLite versions before 3.53.2, though the input data only explicitly mentions version =3.0 and Azure Linux 3.0 without clear version range. No patch or fix details are provided.
Potential Impact
The vulnerability is a memory corruption issue (CWE-122) in SQLite's FTS5 extension, which could lead to instability or potential security risks such as code execution if exploited. However, no confirmed exploitation in the wild is reported, and no detailed impact analysis is available from the provided data.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no patch or official fix information is provided, users should monitor Microsoft Security Response Center advisories for updates. No specific mitigation steps are provided in the available data.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_vex
- Csaf Version
- 2.0
- Publisher
- Microsoft Security Response Center
- Advisory Id
- msrc_CVE-2026-11822
- Cve Count
- 1
Threat ID: 6a2a7b489e049e7b7ee8d23e
Added to database: 06/11/2026, 09:09:28 UTC
Last enriched: 06/11/2026, 09:11:10 UTC
Last updated: 09/14/2026, 22:34:14 UTC
Views: 656
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.