CVE-2025-55132

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Description

A file access flaw has been discovered in NodeJS. A file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can be modified in read-only directories. This behavior could be used to alter timestamps in ways that obscure activity, reducing the reliability of logs.

Metrics

Severity
low
no public PoC known
2.8
Source: nvd-v3
15.2 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-04-10 13:03 UTC

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    node-min20.0.0

  • bitnami

    node-min21.0.0

  • bitnami

    node-min22.22.3

  • bitnami

    node-min23.0.0

  • bitnami

    node-min24.0.0

  • bitnami

    node-min24.16.0

  • bitnami

    node-min25.0.0

  • bitnami

    node-min26.3.0

  • IBM

    App Connect EnterpriseCD 13.4.0

  • IBM

    App Connect EnterpriseLTS 12.0.26

  • IBM

    App Connect EnterpriseLTS 13.4.0

  • IBM

    App Connect Enterprise< 12.0.12.28

    fixed in 12.0.12.28

  • IBM

    App Connect Enterprise< 13.0.8.1

    fixed in 13.0.8.1

  • IBM

    App Connect Enterprise< 13.0.8.2

    fixed in 13.0.8.2

  • IBM

    Concert< 3.0.0

    fixed in 3.0.0

  • juliangruber

    brace-expansion5.0.0 – 5.0.6

  • nodejs

    undici7.23.0 – 7.28.0

  • nodejs

    undici8.0.0 – 8.2.0

  • nodejs

    undici8.0.0 – 8.5.0

  • npm

    undici8.0.0

References & sources

Linked CVEs

IDCVE-2025-55132