Known vulnerabilities in nodejs24 (Red Hat package)

Software CPE: cpe:2.3:o:red_hat:nodejs24_redhat_package:*:*:*:*:*:red_hat_enterprise_linux:*:*
Total vulnerabilities: 29
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 8.8

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting nodejs24 (Red Hat package) nodejs24 (Red Hat package) is affected by 29 known vulnerabilities: 1 high, 19 medium, 9 low Critical High Medium Low

Vulnerabilities (29)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140038 - Resource exhaustion
CVE-2026-56846
CWE-400 Medium
No
No
24.19.0-1.el10_2 29.07.2026 SB2026072975
SB2026083143
SB2026083144
and 6 more
#VU140039 - Use After Free
CVE-2026-56848
CWE-416 Medium
No
No
24.19.0-1.el10_2 29.07.2026 SB2026072975
SB2026083143
SB2026083144
and 6 more
#VU140040 - Improper Access Control
CVE-2026-58043
CWE-284 Low
No
No
24.19.0-1.el10_2 29.07.2026 SB2026072975
SB2026083143
SB2026083144
and 6 more
#VU135820 - Inefficient Algorithmic Complexity
CVE-2026-13149
CWE-407 Medium
No
No
24.18.0-3.el10_2 29.06.2026 SB20260629111
SB2026072843
SB2026072877
and 16 more
#VU135768 - Allocation of Resources Without Limits or Throttling
CVE-2026-59873
CWE-770 Medium
No
No
24.18.0-3.el10_2 29.06.2026 SB2026062990
SB20260728122
SB2026072972
and 8 more
#VU135767 - Loop with Unreachable Exit Condition ('Infinite Loop')
CVE-2026-59874
CWE-835 Medium
No
No
24.18.0-3.el10_2 29.06.2026 SB2026062989
SB20260728122
SB2026072972
and 6 more
#VU127581 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2026-1525
CWE-444 Medium
No
No
24.14.1-2.el10_1 24.04.2026 SB20260424137
SB20260424148
SB20260424149
and 12 more
#VU127579 - Improper Validation of Specified Quantity in Input
CVE-2026-1528
CWE-1284 Medium
No
No
24.14.1-2.el10_1 24.04.2026 SB20260424137
SB20260424148
SB20260424149
and 13 more
#VU127578 - Improper Validation of Specified Quantity in Input
CVE-2026-2229
CWE-1284 Medium
No
No
24.14.1-2.el10_1 24.04.2026 SB20260424137
SB20260424148
SB20260424149
and 12 more
#VU127577 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2026-1527
CWE-93 Low
No
No
24.14.1-2.el10_1 24.04.2026 SB20260424137
SB20260424148
SB20260424153
and 10 more
#VU127576 - Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-1526
CWE-409 Medium
No
No
24.14.1-2.el10_1 24.04.2026 SB20260424137
SB20260424148
SB20260424149
and 12 more
#VU127046 - Improper input validation
CVE-2026-27135
CWE-20 Medium
No
No
24.14.1-2.el10_1 23.04.2026 SB2026042395
SB20260423101
SB20260423102
and 33 more
#VU124546 - Missing release of memory after effective lifetime
CVE-2026-21714
CWE-401 Medium
No
No
24.14.1-2.el10_1 25.03.2026 SB20260325154
SB2026032902
SB20260415182
and 20 more
#VU124547 - Creation of chroot Jail Without Changing Working Directory
CVE-2026-21717
CWE-243 Medium
No
No
24.14.1-2.el10_1 25.03.2026 SB20260325154
SB2026032902
SB20260415182
and 17 more
#VU124548 - Improper Access Control
CVE-2026-21715
CWE-284 Low
No
No
24.14.1-2.el10_1 25.03.2026 SB20260325154
SB2026032902
SB2026041564
and 18 more
#VU124549 - Improper Access Control
CVE-2026-21716
CWE-284 Low
No
No
24.14.1-2.el10_1 25.03.2026 SB20260325154
SB2026032902
SB20260415182
and 18 more
#VU124542 - Error Handling
CVE-2026-21710
CWE-388 Medium
No
No
24.14.1-2.el10_1 25.03.2026 SB20260325154
SB2026032902
SB2026041056
and 30 more
#VU124543 - Improper Access Control
CVE-2026-21711
CWE-284 Low
No
No
24.14.1-2.el10_1 25.03.2026 SB20260325154
SB20260424153
SB20260424154
and 1 more
#VU124544 - Reachable Assertion
CVE-2026-21712
CWE-617 Medium
No
No
24.14.1-2.el10_1 25.03.2026 SB20260325154
SB2026041725
SB20260424153
and 2 more
#VU124545 - Information Exposure Through Timing Discrepancy
CVE-2026-21713
CWE-208 Medium
No
No
24.14.1-2.el10_1 25.03.2026 SB20260325154
SB2026032902
SB2026041543
and 19 more


Showing elements 1 - 20 out of 29