Overview
About vulnerability
A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the --allow-net permission.
This vulnerability affects one supported release line: Node.js 26.
Details
- Affected product:
- AlmaLinux 9.2 ESU , TuxCare 9.6 ESU
- Affected packages:
- nodejs @ 16.20.2 (+1 more)