{"id":"RHSA-2026:7378","summary":"Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update","modified":"2026-09-10T10:17:27Z","published":"2026-04-21T10:09:52Z","upstream":["CVE-2025-55130","CVE-2025-55131","CVE-2025-55132","CVE-2025-59464","CVE-2026-2950","CVE-2026-45149","CVE-2026-48615","CVE-2026-48618","CVE-2026-48619","CVE-2026-48928","CVE-2026-48930","CVE-2026-48933","CVE-2026-48934","CVE-2026-48935","CVE-2026-48936","CVE-2026-59868","CVE-2026-59870","CVE-2026-6734","CVE-2026-9675","CVE-2026-9678","CVE-2026-9697"],"references":[{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:7378"},{"type":"ARTICLE","url":"https://images.redhat.com/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-59464"},{"type":"ARTICLE","url":"https://access.redhat.com/security/updates/classification/"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-55132"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-55131"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2025-55130"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-2950"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-45149"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-9697"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-6734"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-9675"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-9678"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48618"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48933"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48615"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48936"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48934"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48928"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48930"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48619"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-48935"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-59870"},{"type":"REPORT","url":"https://access.redhat.com/security/cve/CVE-2026-59868"},{"type":"ADVISORY","url":"https://security.access.redhat.com/data/csaf/v2/advisories/2026/rhsa-2026_7378.json"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2431352"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2025-55130"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55130"},{"type":"ARTICLE","url":"https://nodejs.org/en/blog/vulnerability/december-2025-security-releases"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2431350"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2025-55131"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55131"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2431338"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2025-55132"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-55132"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2431344"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2025-59464"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59464"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2453499"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-2950"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-2950"},{"type":"ARTICLE","url":"https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2490024"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-6734"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-6734"},{"type":"ARTICLE","url":"https://cna.openjsf.org/security-advisories.html"},{"type":"ARTICLE","url":"https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2489979"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-9675"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9675"},{"type":"ARTICLE","url":"https://github.com/nodejs/undici/security/advisories/GHSA-38rv-x7px-6hhq"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2490000"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-9678"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9678"},{"type":"ARTICLE","url":"https://github.com/nodejs/undici/security/advisories/GHSA-pr7r-676h-xcf6"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2490018"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-9697"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9697"},{"type":"ARTICLE","url":"https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2483481"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-45149"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-45149"},{"type":"ARTICLE","url":"https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-jxxr-4gwj-5jf2"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493335"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48615"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48615"},{"type":"ARTICLE","url":"https://nodejs.org/en/blog/vulnerability/june-2026-security-releases"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493337"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48618"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48618"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493325"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48619"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48619"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493333"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48928"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48928"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493326"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48930"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48930"},{"type":"ARTICLE","url":"https://github.com/nodejs/node/commit/7dafafa2424710ded8b77eb7c878e884c1aef64e"},{"type":"ARTICLE","url":"https://hackerone.com/reports/3656716"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493331"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48933"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48933"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493332"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48934"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48934"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493329"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48935"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48935"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2493336"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-48936"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-48936"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2498114"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-59868"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59868"},{"type":"ARTICLE","url":"https://github.com/nodeca/js-yaml/commit/3105455b81dee69e0fd36e09ac0b2ccfdb54adc1"},{"type":"ARTICLE","url":"https://github.com/nodeca/js-yaml/releases/tag/5.2.0"},{"type":"ARTICLE","url":"https://github.com/nodeca/js-yaml/security/advisories/GHSA-g796-fgmg-93mv"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2498130"},{"type":"ADVISORY","url":"https://www.cve.org/CVERecord?id=CVE-2026-59870"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59870"},{"type":"ARTICLE","url":"https://github.com/nodeca/js-yaml/commit/39f3211a2f01b3c6982710cf21434ab7060acefe"},{"type":"ARTICLE","url":"https://github.com/nodeca/js-yaml/releases/tag/5.2.1"},{"type":"ARTICLE","url":"https://github.com/nodeca/js-yaml/security/advisories/GHSA-724g-mxrg-4qvm"}],"affected":[{"package":{"name":"nodejs25","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/nodejs25"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:25.9.0-1.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:7378.json"}},{"package":{"name":"nodejs25-bin","ecosystem":"Red Hat:hummingbird:1","purl":"pkg:rpm/redhat/nodejs25-bin"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0:25.9.0-1.1.hum1"}]}],"database_specific":{"source":"https://security.access.redhat.com/data/osv/RHSA-2026:7378.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N"}]}