[El-errata] ELSA-2026-7080 Important: Oracle Linux 10 nodejs22 security update

Errata Announcements for Oracle Linux el-errata at oss.oracle.com
Tue Apr 14 04:56:02 UTC 2026


Oracle Linux Security Advisory ELSA-2026-7080

http://linux.oracle.com/errata/ELSA-2026-7080.html

The following updated rpms for Oracle Linux 10 have been uploaded to the Unbreakable Linux Network:

x86_64:
nodejs-22.22.2-1.el10_1.x86_64.rpm
nodejs-devel-22.22.2-1.el10_1.x86_64.rpm
nodejs-docs-22.22.2-1.el10_1.noarch.rpm
nodejs-full-i18n-22.22.2-1.el10_1.x86_64.rpm
nodejs-libs-22.22.2-1.el10_1.x86_64.rpm
nodejs-npm-10.9.7-1.22.22.2.1.el10_1.x86_64.rpm

aarch64:
nodejs-22.22.2-1.el10_1.aarch64.rpm
nodejs-devel-22.22.2-1.el10_1.aarch64.rpm
nodejs-docs-22.22.2-1.el10_1.noarch.rpm
nodejs-full-i18n-22.22.2-1.el10_1.aarch64.rpm
nodejs-libs-22.22.2-1.el10_1.aarch64.rpm
nodejs-npm-10.9.7-1.22.22.2.1.el10_1.aarch64.rpm


SRPMS:
http://oss.oracle.com/ol10/SRPMS-updates/nodejs22-22.22.2-1.el10_1.src.rpm

Related CVEs:

CVE-2026-1525
CVE-2026-1526
CVE-2026-1528
CVE-2026-2229
CVE-2026-21710
CVE-2026-25547
CVE-2026-26996
CVE-2026-27135
CVE-2026-27904




Description of changes:

[1:22.22.2-1]
- Update to version 22.22.2
- introduced patch updating deps/nghttp2 to v 1.68.1 for CVE-2026-27135
- disabled failing tests in nghttp2 due to newer version
- patch for npm/braces CVE-2026-25547

[1:22.22.0-4]
- sources: changed ICU version syntax




More information about the El-errata mailing list