Fedora Account System
Red Hat Associate
Red Hat Customer
A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. Under `--permission`, an attacker who is granted access to one path can abuse boundary handling to read from or write to paths outside the intended filesystem allowlist. This vulnerability affects Node.js **main**, **22.x**, **24.x**, and **26.x**.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:61376 https://access.redhat.com/errata/RHSA-2026:61376
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:61377 https://access.redhat.com/errata/RHSA-2026:61377
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:61386 https://access.redhat.com/errata/RHSA-2026:61386
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:61383 https://access.redhat.com/errata/RHSA-2026:61383
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:62219 https://access.redhat.com/errata/RHSA-2026:62219
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:62416 https://access.redhat.com/errata/RHSA-2026:62416
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:62583 https://access.redhat.com/errata/RHSA-2026:62583
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:64817 https://access.redhat.com/errata/RHSA-2026:64817