VDB
RHSA-2025%3A1611
RHSA-2025%3A1611
PUBLISHED
CVSS 7.699999809265137 HIGH
Red Hat Security Advisory: nodejs:22 security update
Risk Scores
CVSS 3.0
7.699999809265137
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat:enterprise_linux:8::appstream | nodejs-debuginfo | 0, 0 |
| Red Hat:enterprise_linux:8::appstream | nodejs-libs-debuginfo | 0, 0 |
| Red Hat:enterprise_linux:8::appstream | npm | 0, 0 |
| Red Hat:enterprise_linux:8::appstream | nodejs | 0, 0 |
| Red Hat:enterprise_linux:8::appstream | nodejs-full-i18n | 0, 0 |
| Red Hat:enterprise_linux:8::appstream | nodejs-libs | 0, 0 |
| Red Hat:enterprise_linux:8::appstream | nodejs-docs | 0, 0 |
| Red Hat:enterprise_linux:8::appstream | nodejs-nodemon | 0, 0 |
| Red Hat:enterprise_linux:8::appstream | nodejs-packaging | 0, 0 |
| Red Hat:enterprise_linux:8::appstream | nodejs-devel | 0, 0 |
| Red Hat:enterprise_linux:8::appstream | nodejs-debugsource | 0, 0 |
| Red Hat:enterprise_linux:8::appstream | nodejs-packaging-bundler | 0, 0 |
| Red Hat:enterprise_linux:8::appstream | v8-12.4-devel | 0, 0 |
Timeline
- Feb 18, 2025 CVE Published
- May 1, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2025:1611 advisory
- https://access.redhat.com/security/updates/classification/#important article
- https://bugzilla.redhat.com/show_bug.cgi?id=2339176 report
- https://bugzilla.redhat.com/show_bug.cgi?id=2339392 report
- https://bugzilla.redhat.com/show_bug.cgi?id=2342618 report
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1611.json advisory
- https://access.redhat.com/security/cve/CVE-2025-22150 report
- https://www.cve.org/CVERecord?id=CVE-2025-22150 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-22150 advisory
- https://blog.securityevaluators.com/hacking-the-javascript-lottery-80cc437e3b7f article
- https://github.com/nodejs/undici/blob/8b06b8250907d92fead664b3368f1d2aa27c1f35/lib/web/fetch/body.js#L113 article
- https://github.com/nodejs/undici/commit/711e20772764c29f6622ddc937c63b6eefdf07d0 article
- https://github.com/nodejs/undici/commit/c2d78cd19fe4f4c621424491e26ce299e65e934a article
- https://github.com/nodejs/undici/commit/c3acc6050b781b827d80c86cbbab34f14458d385 article
- https://github.com/nodejs/undici/security/advisories/GHSA-c76h-2ccp-4975 article
- https://hackerone.com/reports/2913312 article
- https://access.redhat.com/security/cve/CVE-2025-23083 report
- https://www.cve.org/CVERecord?id=CVE-2025-23083 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-23083 advisory
- https://nodejs.org/en/blog/vulnerability/january-2025-security-releases article
…and 4 more