[CLSA-2026:1785518790] alt-nodejs20-nodejs: Fix of 7 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-07-31 17:26:46 UTC
Description:
- CVE-2026-48617: gate process.report.writeReport() on the fs.write permission so diagnostic reports cannot escape the --allow-fs-write allow-list - CVE-2026-48935: disable FileHandle.utimes() when the Permission Model is enabled so file timestamps cannot be changed with read-only access
Updated packages:
  • alt-nodejs20-nodejs-20.20.2-6.el10.x86_64.rpm
    sha:def2b173cfc39cc2340f7846bec174bdee2dd331fbd0dd31180739eee77463d3
  • alt-nodejs20-nodejs-devel-20.20.2-6.el10.x86_64.rpm
    sha:f8d31705c7ae2c413d0dd92ddb9c8aab7ea4fef8d4e861ecdc706d4f166ba890
  • alt-nodejs20-nodejs-docs-20.20.2-6.el10.noarch.rpm
    sha:0e995a5e42649ea8867d2408d8ac1fe5d1fdbfc6127b8f72aea619f8c1aece89
  • alt-nodejs20-npm-10.8.2-20.20.2.6.el10.x86_64.rpm
    sha:5d84cefd70addd245d02a560e81ddeb5ffb45cbd0eaaf50718aaeef91626d029
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.