CVE-2025-55132
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Description
A file access flaw has been discovered in NodeJS. A file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs.
Metrics
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
bitnami
node-min20.0.0
bitnami
node-min21.0.0
bitnami
node-min22.22.3
bitnami
node-min23.0.0
bitnami
node-min24.0.0
bitnami
node-min24.16.0
bitnami
node-min25.0.0
bitnami
node-min26.3.0
IBM
App Connect EnterpriseCD 13.4.0
IBM
App Connect EnterpriseLTS 12.0.26
IBM
App Connect EnterpriseLTS 13.4.0
IBM
App Connect Enterprise< 12.0.12.28
fixed in 12.0.12.28
IBM
App Connect Enterprise< 13.0.8.1
fixed in 13.0.8.1
IBM
App Connect Enterprise< 13.0.8.2
fixed in 13.0.8.2
IBM
Concert< 3.0.0
fixed in 3.0.0
juliangruber
brace-expansion5.0.0 – 5.0.6
nodejs
undici7.23.0 – 7.28.0
nodejs
undici8.0.0 – 8.2.0
nodejs
undici8.0.0 – 8.5.0
npm
undici8.0.0
References & sources
- https://nodejs.org/en/blog/vulnerability/june-2026-security-releasesweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-48619web
- https://github.com/nodeca/js-yaml/security/advisories/GHSA-g796-fgmg-93mvweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-59868advisory
- https://github.com/nodeca/js-yaml/commit/3105455b81dee69e0fd36e09ac0b2ccfdb54adc1web
- https://github.com/nodeca/js-yamlpackage
- https://github.com/nodeca/js-yaml/releases/tag/5.2.0web
- https://github.com/nodeca/js-yaml/security/advisories/GHSA-724g-mxrg-4qvmweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-59870advisory
- https://github.com/nodeca/js-yaml/commit/39f3211a2f01b3c6982710cf21434ab7060acefeweb
- https://github.com/nodeca/js-yaml/releases/tag/5.2.1web
- https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-jxxr-4gwj-5jf2web
- https://nvd.nist.gov/vuln/detail/CVE-2026-45149advisory
- https://github.com/juliangruber/brace-expansion/commit/c0b095bdc52bc4c36dc88deddbadabc49f8371e5web
- https://github.com/juliangruber/brace-expansionpackage
- https://nodejs.org/en/blog/vulnerability/december-2025-security-releases
- https://nvd.nist.gov/vuln/detail/CVE-2025-55132web
- https://nvd.nist.gov/vuln/detail/CVE-2026-48936web
- https://nvd.nist.gov/vuln/detail/CVE-2026-48615web
- https://github.com/nodejs/undici/security/advisories/GHSA-38rv-x7px-6hhqweb
Linked CVEs
- CVE-2026-9697
A flaw was found in undici.
highCVSSv3 7.4 - CVE-2026-9678
A flaw was found in Undici.
mediumCVSSv3 5.9 - CVE-2026-9675
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-6734
A flaw was found in undici.
highCVSSv3 8.8 - CVE-2026-59870
A flaw was found in js-yaml, a JavaScript YAML (YAML Ain't Markup Language) parser.
highCVSSv3 7.5 - CVE-2026-59868
A flaw was found in js-yaml, a JavaScript YAML parser and dumper.
highCVSSv3 7.5 - CVE-2026-48936
A flaw was found in Node.js.
lowCVSSv3 3.3 - CVE-2026-48935
A flaw was found in Node.js.
lowCVSSv3 3.3 - CVE-2026-48934
A flaw was found in Node.js.
mediumCVSSv3 4.3 - CVE-2026-48933
A flaw was found in the Node.js WebCrypto implementation.
highCVSSv3 7.5 - CVE-2026-48930
A flaw was found in Node.js.
mediumCVSSv3 5.6 - CVE-2026-48928
A flaw was found in Node.js.
mediumCVSSv3 4.2 - CVE-2026-48619
A flaw was found in Node.js.
mediumCVSSv3 5.3 - CVE-2026-48618
A flaw was found in Node.js.
highCVSSv3 7.7 - CVE-2026-48615
A flaw was found in Node.js.
mediumCVSSv3 5.9 - CVE-2026-45149
A flaw was found in the brace-expansion library.
highCVSSv3 7.5 - CVE-2026-2950
A flaw was found in Lodash.
mediumCVSSv3 6.5 - CVE-2025-59464
A resource consumption flaw has been discovered in NodeJS.
mediumCVSSv3 6.5 - CVE-2025-55131
A memory exposure flaw has been discovered in Node.js.
highCVSSv3 7.1 - CVE-2025-55130
A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted rela…
highCVSSv3 7.1