Cross-site scripting in ip-address - CVE-2026-42338
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim\'s browser.
The vulnerability exists due to cross-site scripting in Address6.group(), Address6.link(), and AddressError.parseMessage handling when rendering untrusted Address6 input or related HTML output as HTML. A remote attacker can supply crafted input or option values to inject script and execute arbitrary script in a victim\'s browser.
User interaction is required because a victim application must render the returned HTML or parseMessage as HTML.
Affected software
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Fedora
Red Hat OpenShift Container Platform
nodejs22 (Red Hat package)
nodejs22
nodejs24
How to mitigate CVE-2026-42338
Red Hat OpenShift Container Platform - addressed in versions 4.20.31, 4.21.26
nodejs22 (Red Hat package) - update to 22.23.1-2.el10_0
nodejs22 - update to 22.23.1-2.fc44
nodejs24 - update to 24.18.0-1.fc44
External References
Related Security Bulletins
- Cross-site scripting in ip-address
- Fedora 44 update for nodejs24
- Fedora 44 update for nodejs22
- Red Hat Enterprise Linux 9 update for the nodejs:24 module
- Red Hat Enterprise Linux 9 update for the nodejs:22 module
- Red Hat Enterprise Linux 10 update for nodejs22
- Red Hat Enterprise Linux 8 update for the nodejs:24 module
- Red Hat Enterprise Linux 8 update for the nodejs:22 module
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.20
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.21