[CLSA-2026:1786619031] alt-nodejs14-nodejs: Fix of CVE-2026-48931
Type:
security
Severity:
Low
Release date:
2026-08-13 11:04:03 UTC
Description:
- CVE-2023-39333: module: stop code injection through WebAssembly export names in lib/internal/modules/esm/create_dynamic_module.js -- the ESM facade now uses index-derived local bindings and a JSONStringify-quoted import.meta.exports key instead of interpolating the attacker-controlled export name into code position (adapted from nodejs/node@eaf9083c: V8 8.4 has no ES2022 arbitrary module namespace names, so the `export { ... as NAME }` clause is emitted only for names matching the IdentifierName grammar) - CVE-2026-48931: http: destroy keep-alive sockets that receive unsolicited data while idle in the Agent freeSockets pool, closing the response-queue poisoning window left open once responseKeepAlive() detaches the parser and its 'data' listener (backport of nodejs/node@0a22d401 squashed with its regression follow-up nodejs/node@eaa29254, which guards the idle socket at the handle level instead of attaching a public 'data' listener plus resume())
CVEs fixed:
Updated packages:
  • alt-nodejs14-nodejs-14.21.3-25.el10.x86_64.rpm
    sha:2e2a0b346cba43db9684f0165c1266bbcab4c978cbbe18a7bb7ce47ae4b19b41
  • alt-nodejs14-nodejs-devel-14.21.3-25.el10.x86_64.rpm
    sha:1bec05b9c1de21d92178574052427f80d698036652ea991feec08c90a746eb8c
  • alt-nodejs14-nodejs-docs-14.21.3-25.el10.noarch.rpm
    sha:85f9625c2400d8fd1e7535064e2928cc8aa957b4a608e6f5d1f3b6ccb558e698
  • alt-nodejs14-npm-6.14.18-14.21.3.25.el10.x86_64.rpm
    sha:9e8ba16ac21bbab563af41556104ffbc42b9cd3c9cd0e659ed7614ee71e45000
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.