{
  "document": {
    "aggregate_severity": {
      "text": "High"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_alt_nodejs/alpinelinux3.24/vex/2018/cve-2018-7158-els_alt_nodejs-alpinelinux3_24.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-31T12:46:32Z",
      "generator": {
        "date": "2026-07-31T12:46:31Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2018-7158-ELS_ALT_NODEJS-ALPINELINUX3.24",
      "initial_release_date": "2018-05-17T14:29:00Z",
      "revision_history": [
        {
          "date": "2018-05-17T14:29:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-28T12:26:08Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-30T18:30:46Z",
          "number": "3",
          "summary": "Update document"
        },
        {
          "date": "2026-07-31T12:46:32Z",
          "number": "4",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "4"
    },
    "title": "Security update on CVE-2018-7158"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Alpine Linux 3.24",
                "product": {
                  "name": "Alpine Linux 3.24",
                  "product_id": "Alpine-Linux-3.24",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:alpinelinux:alpine_linux:3.24:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Alpine Linux"
          }
        ],
        "category": "vendor",
        "name": "Alpine Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-nodejs18-dev-18.20.8-r14.aarch64",
                "product": {
                  "name": "alt-nodejs18-dev-18.20.8-r14.aarch64",
                  "product_id": "alt-nodejs18-dev-18.20.8-r14.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-dev@18.20.8-r14?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-18.20.8-r14.aarch64",
                "product": {
                  "name": "alt-nodejs18-18.20.8-r14.aarch64",
                  "product_id": "alt-nodejs18-18.20.8-r14.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18@18.20.8-r14?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-doc-18.20.8-r14.aarch64",
                "product": {
                  "name": "alt-nodejs18-doc-18.20.8-r14.aarch64",
                  "product_id": "alt-nodejs18-doc-18.20.8-r14.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-doc@18.20.8-r14?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-npm-18.20.8-r14.aarch64",
                "product": {
                  "name": "alt-nodejs18-npm-18.20.8-r14.aarch64",
                  "product_id": "alt-nodejs18-npm-18.20.8-r14.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-npm@18.20.8-r14?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-doc-23.11.1-r15.aarch64",
                "product": {
                  "name": "alt-nodejs23-doc-23.11.1-r15.aarch64",
                  "product_id": "alt-nodejs23-doc-23.11.1-r15.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-doc@23.11.1-r15?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-dev-23.11.1-r15.aarch64",
                "product": {
                  "name": "alt-nodejs23-dev-23.11.1-r15.aarch64",
                  "product_id": "alt-nodejs23-dev-23.11.1-r15.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-dev@23.11.1-r15?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-23.11.1-r15.aarch64",
                "product": {
                  "name": "alt-nodejs23-23.11.1-r15.aarch64",
                  "product_id": "alt-nodejs23-23.11.1-r15.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23@23.11.1-r15?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-npm-23.11.1-r15.aarch64",
                "product": {
                  "name": "alt-nodejs23-npm-23.11.1-r15.aarch64",
                  "product_id": "alt-nodejs23-npm-23.11.1-r15.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-npm@23.11.1-r15?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-doc-14.21.3-r25.aarch64",
                "product": {
                  "name": "alt-nodejs14-doc-14.21.3-r25.aarch64",
                  "product_id": "alt-nodejs14-doc-14.21.3-r25.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-doc@14.21.3-r25?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-dev-14.21.3-r25.aarch64",
                "product": {
                  "name": "alt-nodejs14-dev-14.21.3-r25.aarch64",
                  "product_id": "alt-nodejs14-dev-14.21.3-r25.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-dev@14.21.3-r25?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-npm-14.21.3-r25.aarch64",
                "product": {
                  "name": "alt-nodejs14-npm-14.21.3-r25.aarch64",
                  "product_id": "alt-nodejs14-npm-14.21.3-r25.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-npm@14.21.3-r25?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-14.21.3-r25.aarch64",
                "product": {
                  "name": "alt-nodejs14-14.21.3-r25.aarch64",
                  "product_id": "alt-nodejs14-14.21.3-r25.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14@14.21.3-r25?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-dev-16.20.2-r20.aarch64",
                "product": {
                  "name": "alt-nodejs16-dev-16.20.2-r20.aarch64",
                  "product_id": "alt-nodejs16-dev-16.20.2-r20.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-dev@16.20.2-r20?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-16.20.2-r20.aarch64",
                "product": {
                  "name": "alt-nodejs16-16.20.2-r20.aarch64",
                  "product_id": "alt-nodejs16-16.20.2-r20.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16@16.20.2-r20?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-npm-16.20.2-r20.aarch64",
                "product": {
                  "name": "alt-nodejs16-npm-16.20.2-r20.aarch64",
                  "product_id": "alt-nodejs16-npm-16.20.2-r20.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-npm@16.20.2-r20?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-doc-16.20.2-r20.aarch64",
                "product": {
                  "name": "alt-nodejs16-doc-16.20.2-r20.aarch64",
                  "product_id": "alt-nodejs16-doc-16.20.2-r20.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-doc@16.20.2-r20?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-npm-18.20.8-r17.aarch64",
                "product": {
                  "name": "alt-nodejs18-npm-18.20.8-r17.aarch64",
                  "product_id": "alt-nodejs18-npm-18.20.8-r17.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-npm@18.20.8-r17?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-dev-18.20.8-r17.aarch64",
                "product": {
                  "name": "alt-nodejs18-dev-18.20.8-r17.aarch64",
                  "product_id": "alt-nodejs18-dev-18.20.8-r17.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-dev@18.20.8-r17?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-doc-18.20.8-r17.aarch64",
                "product": {
                  "name": "alt-nodejs18-doc-18.20.8-r17.aarch64",
                  "product_id": "alt-nodejs18-doc-18.20.8-r17.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-doc@18.20.8-r17?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-18.20.8-r17.aarch64",
                "product": {
                  "name": "alt-nodejs18-18.20.8-r17.aarch64",
                  "product_id": "alt-nodejs18-18.20.8-r17.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18@18.20.8-r17?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-nodejs18-dev-18.20.8-r14.x86_64",
                "product": {
                  "name": "alt-nodejs18-dev-18.20.8-r14.x86_64",
                  "product_id": "alt-nodejs18-dev-18.20.8-r14.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-dev@18.20.8-r14?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-18.20.8-r14.x86_64",
                "product": {
                  "name": "alt-nodejs18-18.20.8-r14.x86_64",
                  "product_id": "alt-nodejs18-18.20.8-r14.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18@18.20.8-r14?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-doc-18.20.8-r14.x86_64",
                "product": {
                  "name": "alt-nodejs18-doc-18.20.8-r14.x86_64",
                  "product_id": "alt-nodejs18-doc-18.20.8-r14.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-doc@18.20.8-r14?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-npm-18.20.8-r14.x86_64",
                "product": {
                  "name": "alt-nodejs18-npm-18.20.8-r14.x86_64",
                  "product_id": "alt-nodejs18-npm-18.20.8-r14.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-npm@18.20.8-r14?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-doc-23.11.1-r15.x86_64",
                "product": {
                  "name": "alt-nodejs23-doc-23.11.1-r15.x86_64",
                  "product_id": "alt-nodejs23-doc-23.11.1-r15.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-doc@23.11.1-r15?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-dev-23.11.1-r15.x86_64",
                "product": {
                  "name": "alt-nodejs23-dev-23.11.1-r15.x86_64",
                  "product_id": "alt-nodejs23-dev-23.11.1-r15.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-dev@23.11.1-r15?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-23.11.1-r15.x86_64",
                "product": {
                  "name": "alt-nodejs23-23.11.1-r15.x86_64",
                  "product_id": "alt-nodejs23-23.11.1-r15.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23@23.11.1-r15?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-npm-23.11.1-r15.x86_64",
                "product": {
                  "name": "alt-nodejs23-npm-23.11.1-r15.x86_64",
                  "product_id": "alt-nodejs23-npm-23.11.1-r15.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-npm@23.11.1-r15?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-doc-14.21.3-r25.x86_64",
                "product": {
                  "name": "alt-nodejs14-doc-14.21.3-r25.x86_64",
                  "product_id": "alt-nodejs14-doc-14.21.3-r25.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-doc@14.21.3-r25?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-dev-14.21.3-r25.x86_64",
                "product": {
                  "name": "alt-nodejs14-dev-14.21.3-r25.x86_64",
                  "product_id": "alt-nodejs14-dev-14.21.3-r25.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-dev@14.21.3-r25?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-npm-14.21.3-r25.x86_64",
                "product": {
                  "name": "alt-nodejs14-npm-14.21.3-r25.x86_64",
                  "product_id": "alt-nodejs14-npm-14.21.3-r25.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-npm@14.21.3-r25?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-14.21.3-r25.x86_64",
                "product": {
                  "name": "alt-nodejs14-14.21.3-r25.x86_64",
                  "product_id": "alt-nodejs14-14.21.3-r25.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14@14.21.3-r25?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-dev-16.20.2-r20.x86_64",
                "product": {
                  "name": "alt-nodejs16-dev-16.20.2-r20.x86_64",
                  "product_id": "alt-nodejs16-dev-16.20.2-r20.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-dev@16.20.2-r20?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-16.20.2-r20.x86_64",
                "product": {
                  "name": "alt-nodejs16-16.20.2-r20.x86_64",
                  "product_id": "alt-nodejs16-16.20.2-r20.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16@16.20.2-r20?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-npm-16.20.2-r20.x86_64",
                "product": {
                  "name": "alt-nodejs16-npm-16.20.2-r20.x86_64",
                  "product_id": "alt-nodejs16-npm-16.20.2-r20.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-npm@16.20.2-r20?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-doc-16.20.2-r20.x86_64",
                "product": {
                  "name": "alt-nodejs16-doc-16.20.2-r20.x86_64",
                  "product_id": "alt-nodejs16-doc-16.20.2-r20.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-doc@16.20.2-r20?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-npm-18.20.8-r17.x86_64",
                "product": {
                  "name": "alt-nodejs18-npm-18.20.8-r17.x86_64",
                  "product_id": "alt-nodejs18-npm-18.20.8-r17.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-npm@18.20.8-r17?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-dev-18.20.8-r17.x86_64",
                "product": {
                  "name": "alt-nodejs18-dev-18.20.8-r17.x86_64",
                  "product_id": "alt-nodejs18-dev-18.20.8-r17.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-dev@18.20.8-r17?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-doc-18.20.8-r17.x86_64",
                "product": {
                  "name": "alt-nodejs18-doc-18.20.8-r17.x86_64",
                  "product_id": "alt-nodejs18-doc-18.20.8-r17.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-doc@18.20.8-r17?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-18.20.8-r17.x86_64",
                "product": {
                  "name": "alt-nodejs18-18.20.8-r17.x86_64",
                  "product_id": "alt-nodejs18-18.20.8-r17.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18@18.20.8-r17?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-dev-18.20.8-r14.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.aarch64"
        },
        "product_reference": "alt-nodejs18-dev-18.20.8-r14.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-dev-18.20.8-r14.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.x86_64"
        },
        "product_reference": "alt-nodejs18-dev-18.20.8-r14.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-18.20.8-r14.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.aarch64"
        },
        "product_reference": "alt-nodejs18-18.20.8-r14.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-18.20.8-r14.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.x86_64"
        },
        "product_reference": "alt-nodejs18-18.20.8-r14.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-doc-18.20.8-r14.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.x86_64"
        },
        "product_reference": "alt-nodejs18-doc-18.20.8-r14.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-doc-18.20.8-r14.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.aarch64"
        },
        "product_reference": "alt-nodejs18-doc-18.20.8-r14.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-npm-18.20.8-r14.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.aarch64"
        },
        "product_reference": "alt-nodejs18-npm-18.20.8-r14.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-npm-18.20.8-r14.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.x86_64"
        },
        "product_reference": "alt-nodejs18-npm-18.20.8-r14.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-doc-23.11.1-r15.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.aarch64"
        },
        "product_reference": "alt-nodejs23-doc-23.11.1-r15.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-doc-23.11.1-r15.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.x86_64"
        },
        "product_reference": "alt-nodejs23-doc-23.11.1-r15.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-dev-23.11.1-r15.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.x86_64"
        },
        "product_reference": "alt-nodejs23-dev-23.11.1-r15.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-dev-23.11.1-r15.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.aarch64"
        },
        "product_reference": "alt-nodejs23-dev-23.11.1-r15.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-23.11.1-r15.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.x86_64"
        },
        "product_reference": "alt-nodejs23-23.11.1-r15.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-23.11.1-r15.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.aarch64"
        },
        "product_reference": "alt-nodejs23-23.11.1-r15.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-npm-23.11.1-r15.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.aarch64"
        },
        "product_reference": "alt-nodejs23-npm-23.11.1-r15.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-npm-23.11.1-r15.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.x86_64"
        },
        "product_reference": "alt-nodejs23-npm-23.11.1-r15.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-doc-14.21.3-r25.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.aarch64"
        },
        "product_reference": "alt-nodejs14-doc-14.21.3-r25.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-doc-14.21.3-r25.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.x86_64"
        },
        "product_reference": "alt-nodejs14-doc-14.21.3-r25.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-dev-14.21.3-r25.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.x86_64"
        },
        "product_reference": "alt-nodejs14-dev-14.21.3-r25.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-dev-14.21.3-r25.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.aarch64"
        },
        "product_reference": "alt-nodejs14-dev-14.21.3-r25.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-npm-14.21.3-r25.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.aarch64"
        },
        "product_reference": "alt-nodejs14-npm-14.21.3-r25.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-npm-14.21.3-r25.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.x86_64"
        },
        "product_reference": "alt-nodejs14-npm-14.21.3-r25.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-14.21.3-r25.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.x86_64"
        },
        "product_reference": "alt-nodejs14-14.21.3-r25.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-14.21.3-r25.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.aarch64"
        },
        "product_reference": "alt-nodejs14-14.21.3-r25.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-dev-16.20.2-r20.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.aarch64"
        },
        "product_reference": "alt-nodejs16-dev-16.20.2-r20.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-dev-16.20.2-r20.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.x86_64"
        },
        "product_reference": "alt-nodejs16-dev-16.20.2-r20.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-16.20.2-r20.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.aarch64"
        },
        "product_reference": "alt-nodejs16-16.20.2-r20.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-16.20.2-r20.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.x86_64"
        },
        "product_reference": "alt-nodejs16-16.20.2-r20.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-npm-16.20.2-r20.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.aarch64"
        },
        "product_reference": "alt-nodejs16-npm-16.20.2-r20.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-npm-16.20.2-r20.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.x86_64"
        },
        "product_reference": "alt-nodejs16-npm-16.20.2-r20.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-doc-16.20.2-r20.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.x86_64"
        },
        "product_reference": "alt-nodejs16-doc-16.20.2-r20.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-doc-16.20.2-r20.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.aarch64"
        },
        "product_reference": "alt-nodejs16-doc-16.20.2-r20.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-npm-18.20.8-r17.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.x86_64"
        },
        "product_reference": "alt-nodejs18-npm-18.20.8-r17.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-npm-18.20.8-r17.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.aarch64"
        },
        "product_reference": "alt-nodejs18-npm-18.20.8-r17.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-dev-18.20.8-r17.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.aarch64"
        },
        "product_reference": "alt-nodejs18-dev-18.20.8-r17.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-dev-18.20.8-r17.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.x86_64"
        },
        "product_reference": "alt-nodejs18-dev-18.20.8-r17.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-doc-18.20.8-r17.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.aarch64"
        },
        "product_reference": "alt-nodejs18-doc-18.20.8-r17.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-doc-18.20.8-r17.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.x86_64"
        },
        "product_reference": "alt-nodejs18-doc-18.20.8-r17.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-18.20.8-r17.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.x86_64"
        },
        "product_reference": "alt-nodejs18-18.20.8-r17.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-18.20.8-r17.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.aarch64"
        },
        "product_reference": "alt-nodejs18-18.20.8-r17.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2018-7158",
      "cwe": {
        "id": "CWE-185",
        "name": "Incorrect Regular Expression"
      },
      "notes": [
        {
          "category": "description",
          "text": "The `'path'` module in the Node.js 4.x release line contains a potential regular expression denial of service (ReDoS) vector. The code in question was replaced in Node.js 6.x and later so this vulnerability only impacts all versions of Node.js 4.x. The regular expression, `splitPathRe`, used within the `'path'` module for the various path parsing functions, including `path.dirname()`, `path.extname()` and `path.parse()` was structured in such a way as to allow an attacker to craft a string, that when passed through one of these functions, could take a significant amount of time to evaluate, potentially leading to a full denial of service.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        },
        {
          "category": "other",
          "text": "TuxCare has assessed that this vulnerability does not impact any currently supported TuxCare products. This evaluation may change as new information becomes available. For additional details regarding this vulnerability and affected products, refer to the provided references.",
          "title": "Statement"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.aarch64",
          "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.x86_64",
          "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.aarch64",
          "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.x86_64",
          "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.aarch64",
          "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.x86_64",
          "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.aarch64",
          "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.x86_64",
          "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.aarch64",
          "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.x86_64",
          "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.aarch64",
          "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.x86_64",
          "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.aarch64",
          "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.x86_64",
          "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.aarch64",
          "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.x86_64",
          "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.aarch64",
          "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.x86_64",
          "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.aarch64",
          "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.x86_64",
          "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.aarch64",
          "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.x86_64",
          "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.aarch64",
          "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-lang/cve/CVE-2018-7158"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/",
          "url": "https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/"
        }
      ],
      "release_date": "2018-05-17T14:29:00Z",
      "scores": [
        {
          "cvss_v2": {
            "accessComplexity": "LOW",
            "accessVector": "NETWORK",
            "authentication": "NONE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 5.0,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
            "version": "2.0"
          },
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        },
        {
          "category": "impact",
          "date": "2026-07-30T13:34:16.230359Z",
          "details": "Not vulnerable\n\nalt-nodejs18 18.20.8: NOT AFFECTED — vulnerable-component-absent: same post-6.x loop-based `lib/path.js`; the only `splitPathRe` string in the tarball is an uninstalled `test/fixtures/postject-copy` fixture.\n\nPlatform in scope: alpinelinux3.24 (alt-nodejs18 18.20.8). No sibling precedent existed for this CVE at this version anywhere in ELSLANG; assessed from the shipped source and build configuration of alt-nodejs18, not from NVD version ranges.\n\nEvidence\n### What the CVE is\n- CVE-2018-7158 (HIGH, CVSS 3.1 7.5 `AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`) — ReDoS in the Node.js **4.x** `path` module. The `splitPathRe` (POSIX) and `splitTailRe`/`splitDeviceRe` (Windows) regexes backing `path.dirname()`, `path.extname()`, `path.parse()`, `path.basename()` could be driven into super-linear evaluation by a crafted path string.\n- The flaw is in Node's own **pure-JavaScript core** (`lib/path.js`). It is **not** in any bundled or linked C dependency, so shared-vs-bundled linkage is not decisive here (linkage still recorded below per ELS-2268).\n\n### Upstream fix commits + first release\n- POSIX: `nodejs/node@4196fcf23ea81e7c3a4301604dd730427a0623af` — \"path: unwind regular expressions in POSIX\" (2018-02-14), `lib/path.js` +220/-38, removes `const splitPathRe =` and `splitPathRe.exec(filename)`. https://github.com/nodejs/node/commit/4196fcf23ea81e7c3a4301604dd730427a0623af\n- Windows: `nodejs/node@bf00665af68c8aaf43112a244535bd1094d68f16` — \"path: unwind regular expressions in Windows\" (2018-02-22), `lib/path.js` +396/-44, removes `const splitTailRe =`, `splitDeviceRe.exec(filename)`, `splitTailRe.exec(tail)`. https://github.com/nodejs/node/commit/bf00665af68c8aaf43112a244535bd1094d68f16\n- Maintenance branch: **v4.x only** (these are backports; main/6.x already carried the rewrite). First-fixed tag: **v4.9.0**, released 2018-03-28 in the March 2018 security releases.\n- Origin of the fixed code: both commit messages state the unwound implementation was copied from the 6.x rewrite `nodejs/node@bca53dce76f9` \"path: refactor for performance and consistency\" (2015-05-23) — first shipped in the 6.x line. All four packages descend from that.\n\n### Vendor statements\n- Node.js advisory (https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/): \"The `'path'` module in the **Node.js 4.x** release line contains a potential regular expression denial of service (ReDoS) vector. … The code in question was replaced in Node.js 6.x and later so this vulnerability only impacts all versions of Node.js 4.x.\"\n- NVD (REST API, CVE-2018-7158): CPE affected ranges are `nodejs 4.0.0–4.1.2` and `nodejs 4.2.0–4.9.1 (LTS)` only. None of 14.21.3 / 16.20.2 / 18.20.8 / 23.11.1 is listed.\n- Debian (https://security-tracker.debian.org/tracker/CVE-2018-7158): all releases `fixed`; unstable resolved at `nodejs 6.0.0~dfsg-1`. bookworm ships `18.20.4+dfsg-1~deb12u2` — same 18.x line we ship — marked fixed.\n- SUSE (https://www.suse.com/security/cve/CVE-2018-7158.html): \"Node.js 4.x is the only affected version line… the problematic code was replaced in Node.js 6.x and later.\"\n- MANDATORY-STOP triage: no vendor raised a negative/hesitant signal contradicting this evaluation. Debian's `unimportant` urgency accompanies a **fixed** status, not a \"won't fix\". No stop condition triggered.\n\n### Source verification (tarballs as shipped, extracted from `<pkg>/node-v<ver>.tar.gz`)",
          "product_ids": [
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.x86_64"
          ]
        },
        {
          "category": "impact",
          "date": "2026-07-30T13:34:10.534010Z",
          "details": "Not vulnerable\n\nalt-nodejs23 23.11.1: NOT AFFECTED — vulnerable-component-absent: same post-6.x loop-based `lib/path.js`; the only `splitPathRe` string in the tarball is an uninstalled `test/fixtures/postject-copy` fixture.\n\nPlatform in scope: alpinelinux3.24 (alt-nodejs23 23.11.1). No sibling precedent existed for this CVE at this version anywhere in ELSLANG; assessed from the shipped source and build configuration of alt-nodejs23, not from NVD version ranges.\n\nEvidence\n### What the CVE is\n- CVE-2018-7158 (HIGH, CVSS 3.1 7.5 `AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`) — ReDoS in the Node.js **4.x** `path` module. The `splitPathRe` (POSIX) and `splitTailRe`/`splitDeviceRe` (Windows) regexes backing `path.dirname()`, `path.extname()`, `path.parse()`, `path.basename()` could be driven into super-linear evaluation by a crafted path string.\n- The flaw is in Node's own **pure-JavaScript core** (`lib/path.js`). It is **not** in any bundled or linked C dependency, so shared-vs-bundled linkage is not decisive here (linkage still recorded below per ELS-2268).\n\n### Upstream fix commits + first release\n- POSIX: `nodejs/node@4196fcf23ea81e7c3a4301604dd730427a0623af` — \"path: unwind regular expressions in POSIX\" (2018-02-14), `lib/path.js` +220/-38, removes `const splitPathRe =` and `splitPathRe.exec(filename)`. https://github.com/nodejs/node/commit/4196fcf23ea81e7c3a4301604dd730427a0623af\n- Windows: `nodejs/node@bf00665af68c8aaf43112a244535bd1094d68f16` — \"path: unwind regular expressions in Windows\" (2018-02-22), `lib/path.js` +396/-44, removes `const splitTailRe =`, `splitDeviceRe.exec(filename)`, `splitTailRe.exec(tail)`. https://github.com/nodejs/node/commit/bf00665af68c8aaf43112a244535bd1094d68f16\n- Maintenance branch: **v4.x only** (these are backports; main/6.x already carried the rewrite). First-fixed tag: **v4.9.0**, released 2018-03-28 in the March 2018 security releases.\n- Origin of the fixed code: both commit messages state the unwound implementation was copied from the 6.x rewrite `nodejs/node@bca53dce76f9` \"path: refactor for performance and consistency\" (2015-05-23) — first shipped in the 6.x line. All four packages descend from that.\n\n### Vendor statements\n- Node.js advisory (https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/): \"The `'path'` module in the **Node.js 4.x** release line contains a potential regular expression denial of service (ReDoS) vector. … The code in question was replaced in Node.js 6.x and later so this vulnerability only impacts all versions of Node.js 4.x.\"\n- NVD (REST API, CVE-2018-7158): CPE affected ranges are `nodejs 4.0.0–4.1.2` and `nodejs 4.2.0–4.9.1 (LTS)` only. None of 14.21.3 / 16.20.2 / 18.20.8 / 23.11.1 is listed.\n- Debian (https://security-tracker.debian.org/tracker/CVE-2018-7158): all releases `fixed`; unstable resolved at `nodejs 6.0.0~dfsg-1`. bookworm ships `18.20.4+dfsg-1~deb12u2` — same 18.x line we ship — marked fixed.\n- SUSE (https://www.suse.com/security/cve/CVE-2018-7158.html): \"Node.js 4.x is the only affected version line… the problematic code was replaced in Node.js 6.x and later.\"\n- MANDATORY-STOP triage: no vendor raised a negative/hesitant signal contradicting this evaluation. Debian's `unimportant` urgency accompanies a **fixed** status, not a \"won't fix\". No stop condition triggered.\n\n### Source verification (tarballs as shipped, extracted from `<pkg>/node-v<ver>.tar.gz`)",
          "product_ids": [
            "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.x86_64"
          ]
        },
        {
          "category": "impact",
          "date": "2026-07-30T13:34:09.727059Z",
          "details": "Not vulnerable\n\nalt-nodejs14 14.21.3: NOT AFFECTED — vulnerable-component-absent: the `splitPathRe`/`splitTailRe`/`splitDeviceRe` regexes that carry the ReDoS were removed from Node core `lib/path.js` in the 6.x rewrite, and 14.21.3 ships the regex-free character-scanning implementation (zero regex literals in the file).\n\nPlatform in scope: alpinelinux3.24 (alt-nodejs14 14.21.3). No sibling precedent existed for this CVE at this version anywhere in ELSLANG; assessed from the shipped source and build configuration of alt-nodejs14, not from NVD version ranges.\n\nEvidence\n### What the CVE is\n- CVE-2018-7158 (HIGH, CVSS 3.1 7.5 `AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`) — ReDoS in the Node.js **4.x** `path` module. The `splitPathRe` (POSIX) and `splitTailRe`/`splitDeviceRe` (Windows) regexes backing `path.dirname()`, `path.extname()`, `path.parse()`, `path.basename()` could be driven into super-linear evaluation by a crafted path string.\n- The flaw is in Node's own **pure-JavaScript core** (`lib/path.js`). It is **not** in any bundled or linked C dependency, so shared-vs-bundled linkage is not decisive here (linkage still recorded below per ELS-2268).\n\n### Upstream fix commits + first release\n- POSIX: `nodejs/node@4196fcf23ea81e7c3a4301604dd730427a0623af` — \"path: unwind regular expressions in POSIX\" (2018-02-14), `lib/path.js` +220/-38, removes `const splitPathRe =` and `splitPathRe.exec(filename)`. https://github.com/nodejs/node/commit/4196fcf23ea81e7c3a4301604dd730427a0623af\n- Windows: `nodejs/node@bf00665af68c8aaf43112a244535bd1094d68f16` — \"path: unwind regular expressions in Windows\" (2018-02-22), `lib/path.js` +396/-44, removes `const splitTailRe =`, `splitDeviceRe.exec(filename)`, `splitTailRe.exec(tail)`. https://github.com/nodejs/node/commit/bf00665af68c8aaf43112a244535bd1094d68f16\n- Maintenance branch: **v4.x only** (these are backports; main/6.x already carried the rewrite). First-fixed tag: **v4.9.0**, released 2018-03-28 in the March 2018 security releases.\n- Origin of the fixed code: both commit messages state the unwound implementation was copied from the 6.x rewrite `nodejs/node@bca53dce76f9` \"path: refactor for performance and consistency\" (2015-05-23) — first shipped in the 6.x line. All four packages descend from that.\n\n### Vendor statements\n- Node.js advisory (https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/): \"The `'path'` module in the **Node.js 4.x** release line contains a potential regular expression denial of service (ReDoS) vector. … The code in question was replaced in Node.js 6.x and later so this vulnerability only impacts all versions of Node.js 4.x.\"\n- NVD (REST API, CVE-2018-7158): CPE affected ranges are `nodejs 4.0.0–4.1.2` and `nodejs 4.2.0–4.9.1 (LTS)` only. None of 14.21.3 / 16.20.2 / 18.20.8 / 23.11.1 is listed.\n- Debian (https://security-tracker.debian.org/tracker/CVE-2018-7158): all releases `fixed`; unstable resolved at `nodejs 6.0.0~dfsg-1`. bookworm ships `18.20.4+dfsg-1~deb12u2` — same 18.x line we ship — marked fixed.\n- SUSE (https://www.suse.com/security/cve/CVE-2018-7158.html): \"Node.js 4.x is the only affected version line… the problematic code was replaced in Node.js 6.x and later.\"\n- MANDATORY-STOP triage: no vendor raised a negative/hesitant signal contradicting this evaluation. Debian's `unimportant` urgency accompanies a **fixed** status, not a \"won't fix\". No stop condition triggered.\n\n### Source verification (tarballs as shipped, extracted from `<pkg>/node-v<ver>.tar.gz`)",
          "product_ids": [
            "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.x86_64"
          ]
        },
        {
          "category": "impact",
          "date": "2026-07-30T13:34:02.061055Z",
          "details": "Not vulnerable\n\nalt-nodejs16 16.20.2: NOT AFFECTED — vulnerable-component-absent: `lib/path.js` uses the unwound loop-based `dirname`/`extname`/`parse` (only remaining regex is the linear `/\\\\/g` in win32 `toNamespacedPath`); none of the three vulnerable regexes exist in Node core.\n\nPlatform in scope: alpinelinux3.24 (alt-nodejs16 16.20.2). No sibling precedent existed for this CVE at this version anywhere in ELSLANG; assessed from the shipped source and build configuration of alt-nodejs16, not from NVD version ranges.\n\nEvidence\n### What the CVE is\n- CVE-2018-7158 (HIGH, CVSS 3.1 7.5 `AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H`) — ReDoS in the Node.js **4.x** `path` module. The `splitPathRe` (POSIX) and `splitTailRe`/`splitDeviceRe` (Windows) regexes backing `path.dirname()`, `path.extname()`, `path.parse()`, `path.basename()` could be driven into super-linear evaluation by a crafted path string.\n- The flaw is in Node's own **pure-JavaScript core** (`lib/path.js`). It is **not** in any bundled or linked C dependency, so shared-vs-bundled linkage is not decisive here (linkage still recorded below per ELS-2268).\n\n### Upstream fix commits + first release\n- POSIX: `nodejs/node@4196fcf23ea81e7c3a4301604dd730427a0623af` — \"path: unwind regular expressions in POSIX\" (2018-02-14), `lib/path.js` +220/-38, removes `const splitPathRe =` and `splitPathRe.exec(filename)`. https://github.com/nodejs/node/commit/4196fcf23ea81e7c3a4301604dd730427a0623af\n- Windows: `nodejs/node@bf00665af68c8aaf43112a244535bd1094d68f16` — \"path: unwind regular expressions in Windows\" (2018-02-22), `lib/path.js` +396/-44, removes `const splitTailRe =`, `splitDeviceRe.exec(filename)`, `splitTailRe.exec(tail)`. https://github.com/nodejs/node/commit/bf00665af68c8aaf43112a244535bd1094d68f16\n- Maintenance branch: **v4.x only** (these are backports; main/6.x already carried the rewrite). First-fixed tag: **v4.9.0**, released 2018-03-28 in the March 2018 security releases.\n- Origin of the fixed code: both commit messages state the unwound implementation was copied from the 6.x rewrite `nodejs/node@bca53dce76f9` \"path: refactor for performance and consistency\" (2015-05-23) — first shipped in the 6.x line. All four packages descend from that.\n\n### Vendor statements\n- Node.js advisory (https://nodejs.org/en/blog/vulnerability/march-2018-security-releases/): \"The `'path'` module in the **Node.js 4.x** release line contains a potential regular expression denial of service (ReDoS) vector. … The code in question was replaced in Node.js 6.x and later so this vulnerability only impacts all versions of Node.js 4.x.\"\n- NVD (REST API, CVE-2018-7158): CPE affected ranges are `nodejs 4.0.0–4.1.2` and `nodejs 4.2.0–4.9.1 (LTS)` only. None of 14.21.3 / 16.20.2 / 18.20.8 / 23.11.1 is listed.\n- Debian (https://security-tracker.debian.org/tracker/CVE-2018-7158): all releases `fixed`; unstable resolved at `nodejs 6.0.0~dfsg-1`. bookworm ships `18.20.4+dfsg-1~deb12u2` — same 18.x line we ship — marked fixed.\n- SUSE (https://www.suse.com/security/cve/CVE-2018-7158.html): \"Node.js 4.x is the only affected version line… the problematic code was replaced in Node.js 6.x and later.\"\n- MANDATORY-STOP triage: no vendor raised a negative/hesitant signal contradicting this evaluation. Debian's `unimportant` urgency accompanies a **fixed** status, not a \"won't fix\". No stop condition triggered.\n\n### Source verification (tarballs as shipped, extracted from `<pkg>/node-v<ver>.tar.gz`)",
          "product_ids": [
            "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.x86_64"
          ]
        }
      ]
    }
  ]
}