Skip to navigation Skip to main content

Utilities

  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
Red Hat Customer Portal
  • Subscriptions
  • Downloads
  • Red Hat Console
  • Get Support
  • Products

    Top Products

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Products

    Downloads and Containers

    • Downloads
    • Packages
    • Containers

    Top Resources

    • Documentation
    • Product Life Cycles
    • Product Compliance
    • Errata
  • Knowledge

    Red Hat Knowledge Center

    • Knowledgebase Solutions
    • Knowledgebase Articles
    • Customer Portal Labs
    • Errata

    Top Product Docs

    • Red Hat Enterprise Linux
    • Red Hat OpenShift
    • Red Hat Ansible Automation Platform
    All Product Docs

    Training and Certification

    • About
    • Course Index
    • Certification Index
    • Skill Assessment
  • Security

    Red Hat Product Security Center

    • Security Updates
    • Security Advisories
    • Red Hat CVE Database
    • Errata

    References

    • Security Bulletins
    • Security Measurement
    • Severity Ratings
    • Security Data

    Top Resources

    • Security Labs
    • Backporting Policies
    • Security Blog
  • Support

    Red Hat Support

    • Support Cases
    • Troubleshoot
    • Get Support
    • Contact Red Hat Support

    Red Hat Community Support

    • Customer Portal Community
    • Community Discussions
    • Red Hat Accelerator Program

    Top Resources

    • Product Life Cycles
    • Customer Portal Labs
    • Red Hat JBoss Supported Configurations
    • Red Hat Lightspeed
Or troubleshoot an issue.

Select Your Language

  • English
  • Français
  • 한국어
  • 日本語
  • 中文 (中国)

Infrastructure and Management

  • Red Hat Enterprise Linux
  • Red Hat Satellite
  • Red Hat Subscription Management
  • Red Hat Lightspeed
  • Red Hat Ansible Automation Platform

Cloud Computing

  • Red Hat OpenShift
  • Red Hat OpenStack Platform
  • Red Hat OpenShift
  • Red Hat OpenShift AI
  • Red Hat OpenShift Dedicated
  • Red Hat Advanced Cluster Security for Kubernetes
  • Red Hat Advanced Cluster Management for Kubernetes
  • Red Hat Quay
  • Red Hat OpenShift Dev Spaces
  • Red Hat OpenShift Service on AWS

Storage

  • Red Hat Gluster Storage
  • Red Hat Hyperconverged Infrastructure
  • Red Hat Ceph Storage
  • Red Hat OpenShift Data Foundation

Runtimes

  • Red Hat Runtimes
  • Red Hat JBoss Enterprise Application Platform
  • Red Hat Data Grid
  • Red Hat JBoss Web Server
  • Red Hat build of Keycloak
  • Red Hat support for Spring Boot
  • Red Hat build of Node.js
  • Red Hat build of Quarkus

Integration and Automation

  • Red Hat Application Foundations
  • Red Hat Fuse
  • Red Hat AMQ
  • Red Hat 3scale API Management
All Products
Red Hat Product Errata RHSA-2025:4461 - Security Advisory
Issued:
2025-05-05
Updated:
2025-05-05

RHSA-2025:4461 - Security Advisory

  • Overview
  • Updated Packages

Synopsis

Moderate: nodejs:20 security update

Type/Severity

Security Advisory: Moderate

Red Hat Lightspeed patch analysis

Identify and remediate systems affected by this advisory.

View affected systems

Topic

An update for the nodejs:20 module is now available for Red Hat Enterprise Linux 8.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.

Security Fix(es):

  • c-ares: c-ares has a use-after-free in read_answers() (CVE-2025-31498)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Affected Products

  • Red Hat Enterprise Linux for x86_64 8 x86_64
  • Red Hat Enterprise Linux for IBM z Systems 8 s390x
  • Red Hat Enterprise Linux for Power, little endian 8 ppc64le
  • Red Hat Enterprise Linux for ARM 64 8 aarch64

Fixes

  • BZ - 2358271 - CVE-2025-31498 c-ares: c-ares has a use-after-free in read_answers()
  • RHEL-78763 - nodejs:20/nodejs: Rebase to the latest Nodejs 20 release [rhel-8]

CVEs

  • CVE-2025-31498

References

  • https://access.redhat.com/security/updates/classification/#moderate
Note: More recent versions of these packages may be available. Click a package name for more details.

Red Hat Enterprise Linux for x86_64 8

SRPM
nodejs-20.19.1-1.module+el8.10.0+23054+5431297f.src.rpm SHA-256: 925221141502b8ca618c7f9894216f5067ae1444ecfb268b1461f6846ba95c3b
nodejs-nodemon-3.0.1-1.module+el8.10.0+22904+d0fedeff.src.rpm SHA-256: 5567d22ddde61b4b4d4de219eb0a0309871c3e9bbf8c6f8af7ace8af4f8fa6af
nodejs-packaging-2021.06-4.module+el8.10.0+22904+d0fedeff.src.rpm SHA-256: a457fc58c3ab08143840d02f28bce7dac0e11f045e2279e730182a52ca622e8c
x86_64
nodejs-docs-20.19.1-1.module+el8.10.0+23054+5431297f.noarch.rpm SHA-256: 1521aa2e4d993d69d99088ad7bafdcaabec897a15cbb2bc2ad8ca2215451bbdc
nodejs-nodemon-3.0.1-1.module+el8.10.0+22904+d0fedeff.noarch.rpm SHA-256: 685c8e7e928f5397c5990c7b7948130016685fe2d233cfc321baac909afa1184
nodejs-packaging-2021.06-4.module+el8.10.0+22904+d0fedeff.noarch.rpm SHA-256: 84187d6ac3846de7091bc769cc416fc94448aeb12e1c62b1eb3540705bdb570f
nodejs-packaging-bundler-2021.06-4.module+el8.10.0+22904+d0fedeff.noarch.rpm SHA-256: d9b450ee71063942e64dbc51e5f3fa4c74b9a23a014da2dce4b44f1de1f36031
nodejs-20.19.1-1.module+el8.10.0+23054+5431297f.x86_64.rpm SHA-256: 8477b7cad5ee389224f6d591a2942f2f11bfea0aef5d02ce81b472493d988ce3
nodejs-debuginfo-20.19.1-1.module+el8.10.0+23054+5431297f.x86_64.rpm SHA-256: 0fa30498012af59fae3423c65cc77a9f765a6acec31b28fa9826b1da4aba7733
nodejs-debugsource-20.19.1-1.module+el8.10.0+23054+5431297f.x86_64.rpm SHA-256: 1f8af2bcbb507012a76b1bf6f11533fdc74c8d85a93502edbd57431649faa205
nodejs-devel-20.19.1-1.module+el8.10.0+23054+5431297f.x86_64.rpm SHA-256: 61a0a4020edc7cfbe8a977765cca6fa78dabd1d951f980444be969a68794bc14
nodejs-full-i18n-20.19.1-1.module+el8.10.0+23054+5431297f.x86_64.rpm SHA-256: 115315f20b77c66ff465d443ff422a578bd8b5e8c92fa7886c8c57e17f94b4e8
npm-10.8.2-1.20.19.1.1.module+el8.10.0+23054+5431297f.x86_64.rpm SHA-256: 3902da2e2b1933fa17933f77f846e0d901d8fd31074ee707239206da7482fba9

Red Hat Enterprise Linux for IBM z Systems 8

SRPM
nodejs-20.19.1-1.module+el8.10.0+23054+5431297f.src.rpm SHA-256: 925221141502b8ca618c7f9894216f5067ae1444ecfb268b1461f6846ba95c3b
nodejs-nodemon-3.0.1-1.module+el8.10.0+22904+d0fedeff.src.rpm SHA-256: 5567d22ddde61b4b4d4de219eb0a0309871c3e9bbf8c6f8af7ace8af4f8fa6af
nodejs-packaging-2021.06-4.module+el8.10.0+22904+d0fedeff.src.rpm SHA-256: a457fc58c3ab08143840d02f28bce7dac0e11f045e2279e730182a52ca622e8c
s390x
nodejs-20.19.1-1.module+el8.10.0+23054+5431297f.s390x.rpm SHA-256: c7ec94a82ea0441578ff576185ed2f8ea7f973807745390108b408a47943f497
nodejs-debuginfo-20.19.1-1.module+el8.10.0+23054+5431297f.s390x.rpm SHA-256: 58bd3e15f1a49aad6087dab59c6189334066d9bc04a89291b2adcb51e4c37a5a
nodejs-debugsource-20.19.1-1.module+el8.10.0+23054+5431297f.s390x.rpm SHA-256: 9e44281a23be7ce51883eadcb08998baef357420700e67aed355906df6e60cf3
nodejs-devel-20.19.1-1.module+el8.10.0+23054+5431297f.s390x.rpm SHA-256: 72f346441e99f4c5dd4108811e46225138db064cf93f38754a1babda1518a8fb
nodejs-docs-20.19.1-1.module+el8.10.0+23054+5431297f.noarch.rpm SHA-256: 1521aa2e4d993d69d99088ad7bafdcaabec897a15cbb2bc2ad8ca2215451bbdc
nodejs-full-i18n-20.19.1-1.module+el8.10.0+23054+5431297f.s390x.rpm SHA-256: 0eae0d5d32c071711855ea58d8a6368607722e7a2271efda65ff24c7d3724380
nodejs-nodemon-3.0.1-1.module+el8.10.0+22904+d0fedeff.noarch.rpm SHA-256: 685c8e7e928f5397c5990c7b7948130016685fe2d233cfc321baac909afa1184
nodejs-packaging-2021.06-4.module+el8.10.0+22904+d0fedeff.noarch.rpm SHA-256: 84187d6ac3846de7091bc769cc416fc94448aeb12e1c62b1eb3540705bdb570f
nodejs-packaging-bundler-2021.06-4.module+el8.10.0+22904+d0fedeff.noarch.rpm SHA-256: d9b450ee71063942e64dbc51e5f3fa4c74b9a23a014da2dce4b44f1de1f36031
npm-10.8.2-1.20.19.1.1.module+el8.10.0+23054+5431297f.s390x.rpm SHA-256: 0a75937e1af8f1f9d360894dff31f1649bc6e44f2fe38b3d62e062568315a2b9

Red Hat Enterprise Linux for Power, little endian 8

SRPM
nodejs-20.19.1-1.module+el8.10.0+23054+5431297f.src.rpm SHA-256: 925221141502b8ca618c7f9894216f5067ae1444ecfb268b1461f6846ba95c3b
nodejs-nodemon-3.0.1-1.module+el8.10.0+22904+d0fedeff.src.rpm SHA-256: 5567d22ddde61b4b4d4de219eb0a0309871c3e9bbf8c6f8af7ace8af4f8fa6af
nodejs-packaging-2021.06-4.module+el8.10.0+22904+d0fedeff.src.rpm SHA-256: a457fc58c3ab08143840d02f28bce7dac0e11f045e2279e730182a52ca622e8c
ppc64le
nodejs-docs-20.19.1-1.module+el8.10.0+23054+5431297f.noarch.rpm SHA-256: 1521aa2e4d993d69d99088ad7bafdcaabec897a15cbb2bc2ad8ca2215451bbdc
nodejs-nodemon-3.0.1-1.module+el8.10.0+22904+d0fedeff.noarch.rpm SHA-256: 685c8e7e928f5397c5990c7b7948130016685fe2d233cfc321baac909afa1184
nodejs-packaging-2021.06-4.module+el8.10.0+22904+d0fedeff.noarch.rpm SHA-256: 84187d6ac3846de7091bc769cc416fc94448aeb12e1c62b1eb3540705bdb570f
nodejs-packaging-bundler-2021.06-4.module+el8.10.0+22904+d0fedeff.noarch.rpm SHA-256: d9b450ee71063942e64dbc51e5f3fa4c74b9a23a014da2dce4b44f1de1f36031
nodejs-20.19.1-1.module+el8.10.0+23054+5431297f.ppc64le.rpm SHA-256: d51d7a242c8f5659ba8ee43166439d6bfaec6cb3ee1a902c997872751f3df7ca
nodejs-debuginfo-20.19.1-1.module+el8.10.0+23054+5431297f.ppc64le.rpm SHA-256: c4137b0a85088c5f10f29a328102e30e1a2b47367d52e3e7ac75bb8e51469f13
nodejs-debugsource-20.19.1-1.module+el8.10.0+23054+5431297f.ppc64le.rpm SHA-256: 15bb0a35d4a04993dfcdb25c72fed9fe5a189d8c99ff558ca046513190456556
nodejs-devel-20.19.1-1.module+el8.10.0+23054+5431297f.ppc64le.rpm SHA-256: bbeef0046978a6f77d96acb97fa2f0dd6413cda497f56bb4d85bac262561f3aa
nodejs-full-i18n-20.19.1-1.module+el8.10.0+23054+5431297f.ppc64le.rpm SHA-256: 2bb1c4095d3ea9ce98d0211df281a946fc6729622ab37a2941cf7f04bd347dae
npm-10.8.2-1.20.19.1.1.module+el8.10.0+23054+5431297f.ppc64le.rpm SHA-256: eaa37df6b07ae067f732710f8930b46285d82c200b3369a1f8fc9c858ace35bf

Red Hat Enterprise Linux for ARM 64 8

SRPM
nodejs-20.19.1-1.module+el8.10.0+23054+5431297f.src.rpm SHA-256: 925221141502b8ca618c7f9894216f5067ae1444ecfb268b1461f6846ba95c3b
nodejs-nodemon-3.0.1-1.module+el8.10.0+22904+d0fedeff.src.rpm SHA-256: 5567d22ddde61b4b4d4de219eb0a0309871c3e9bbf8c6f8af7ace8af4f8fa6af
nodejs-packaging-2021.06-4.module+el8.10.0+22904+d0fedeff.src.rpm SHA-256: a457fc58c3ab08143840d02f28bce7dac0e11f045e2279e730182a52ca622e8c
aarch64
nodejs-docs-20.19.1-1.module+el8.10.0+23054+5431297f.noarch.rpm SHA-256: 1521aa2e4d993d69d99088ad7bafdcaabec897a15cbb2bc2ad8ca2215451bbdc
nodejs-nodemon-3.0.1-1.module+el8.10.0+22904+d0fedeff.noarch.rpm SHA-256: 685c8e7e928f5397c5990c7b7948130016685fe2d233cfc321baac909afa1184
nodejs-packaging-2021.06-4.module+el8.10.0+22904+d0fedeff.noarch.rpm SHA-256: 84187d6ac3846de7091bc769cc416fc94448aeb12e1c62b1eb3540705bdb570f
nodejs-packaging-bundler-2021.06-4.module+el8.10.0+22904+d0fedeff.noarch.rpm SHA-256: d9b450ee71063942e64dbc51e5f3fa4c74b9a23a014da2dce4b44f1de1f36031
nodejs-20.19.1-1.module+el8.10.0+23054+5431297f.aarch64.rpm SHA-256: e607ad1a9d75ebcac490d23220e0adbd119d09c1ebfa1f35015cab327eacc3f4
nodejs-debuginfo-20.19.1-1.module+el8.10.0+23054+5431297f.aarch64.rpm SHA-256: 610950456f272f88c8a0a45c8c2e9be34f06b5433ae0c7c7c22a6af745e29461
nodejs-debugsource-20.19.1-1.module+el8.10.0+23054+5431297f.aarch64.rpm SHA-256: 38c436f833e5bddb27fc9e62c73af075e93764d5871d8033410f3831b322c4bd
nodejs-devel-20.19.1-1.module+el8.10.0+23054+5431297f.aarch64.rpm SHA-256: cc7f0bb8e28ef8d22c5171306b492b0a0963e6df2d5b2922003d3f4e30247924
nodejs-full-i18n-20.19.1-1.module+el8.10.0+23054+5431297f.aarch64.rpm SHA-256: 4ced0c0e32a3e6f6637e7dc167214c1d310db32f130d91e2ff878d9dc088c88b
npm-10.8.2-1.20.19.1.1.module+el8.10.0+23054+5431297f.aarch64.rpm SHA-256: cb5994cb0376e8999994f2664a888ede619f08cc20b2dcda4a98b9efd32838ca

The Red Hat security contact is secalert@redhat.com. More contact details at https://access.redhat.com/security/team/contact/.

Red Hat LinkedIn YouTube Facebook X, formerly Twitter

Quick Links

  • Downloads
  • Subscriptions
  • Support Cases
  • Customer Service
  • Product Documentation

Help

  • Contact Us
  • Customer Portal FAQ
  • Log-in Assistance

Site Info

  • Trust Red Hat
  • Browser Support Policy
  • Accessibility
  • Awards and Recognition
  • Colophon

Related Sites

  • redhat.com
  • developers.redhat.com
  • connect.redhat.com
  • cloud.redhat.com

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2025 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility