{
  "document": {
    "aggregate_severity": {
      "text": "High"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_alt_nodejs/alpinelinux3.24/vex/2018/cve-2018-7167-els_alt_nodejs-alpinelinux3_24.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-31T12:46:35Z",
      "generator": {
        "date": "2026-07-31T12:46:35Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2018-7167-ELS_ALT_NODEJS-ALPINELINUX3.24",
      "initial_release_date": "2018-06-13T16:29:00Z",
      "revision_history": [
        {
          "date": "2018-06-13T16:29:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-28T12:26:02Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-29T08:27:09Z",
          "number": "3",
          "summary": "Update document"
        },
        {
          "date": "2026-07-31T12:46:35Z",
          "number": "4",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "4"
    },
    "title": "Security update on CVE-2018-7167"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Alpine Linux 3.24",
                "product": {
                  "name": "Alpine Linux 3.24",
                  "product_id": "Alpine-Linux-3.24",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:alpinelinux:alpine_linux:3.24:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Alpine Linux"
          }
        ],
        "category": "vendor",
        "name": "Alpine Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-nodejs18-dev-18.20.8-r14.aarch64",
                "product": {
                  "name": "alt-nodejs18-dev-18.20.8-r14.aarch64",
                  "product_id": "alt-nodejs18-dev-18.20.8-r14.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-dev@18.20.8-r14?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-18.20.8-r14.aarch64",
                "product": {
                  "name": "alt-nodejs18-18.20.8-r14.aarch64",
                  "product_id": "alt-nodejs18-18.20.8-r14.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18@18.20.8-r14?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-doc-18.20.8-r14.aarch64",
                "product": {
                  "name": "alt-nodejs18-doc-18.20.8-r14.aarch64",
                  "product_id": "alt-nodejs18-doc-18.20.8-r14.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-doc@18.20.8-r14?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-npm-18.20.8-r14.aarch64",
                "product": {
                  "name": "alt-nodejs18-npm-18.20.8-r14.aarch64",
                  "product_id": "alt-nodejs18-npm-18.20.8-r14.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-npm@18.20.8-r14?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-doc-14.21.3-r25.aarch64",
                "product": {
                  "name": "alt-nodejs14-doc-14.21.3-r25.aarch64",
                  "product_id": "alt-nodejs14-doc-14.21.3-r25.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-doc@14.21.3-r25?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-dev-14.21.3-r25.aarch64",
                "product": {
                  "name": "alt-nodejs14-dev-14.21.3-r25.aarch64",
                  "product_id": "alt-nodejs14-dev-14.21.3-r25.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-dev@14.21.3-r25?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-npm-14.21.3-r25.aarch64",
                "product": {
                  "name": "alt-nodejs14-npm-14.21.3-r25.aarch64",
                  "product_id": "alt-nodejs14-npm-14.21.3-r25.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-npm@14.21.3-r25?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-14.21.3-r25.aarch64",
                "product": {
                  "name": "alt-nodejs14-14.21.3-r25.aarch64",
                  "product_id": "alt-nodejs14-14.21.3-r25.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14@14.21.3-r25?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-doc-23.11.1-r15.aarch64",
                "product": {
                  "name": "alt-nodejs23-doc-23.11.1-r15.aarch64",
                  "product_id": "alt-nodejs23-doc-23.11.1-r15.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-doc@23.11.1-r15?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-dev-23.11.1-r15.aarch64",
                "product": {
                  "name": "alt-nodejs23-dev-23.11.1-r15.aarch64",
                  "product_id": "alt-nodejs23-dev-23.11.1-r15.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-dev@23.11.1-r15?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-23.11.1-r15.aarch64",
                "product": {
                  "name": "alt-nodejs23-23.11.1-r15.aarch64",
                  "product_id": "alt-nodejs23-23.11.1-r15.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23@23.11.1-r15?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-npm-23.11.1-r15.aarch64",
                "product": {
                  "name": "alt-nodejs23-npm-23.11.1-r15.aarch64",
                  "product_id": "alt-nodejs23-npm-23.11.1-r15.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-npm@23.11.1-r15?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-dev-16.20.2-r20.aarch64",
                "product": {
                  "name": "alt-nodejs16-dev-16.20.2-r20.aarch64",
                  "product_id": "alt-nodejs16-dev-16.20.2-r20.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-dev@16.20.2-r20?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-16.20.2-r20.aarch64",
                "product": {
                  "name": "alt-nodejs16-16.20.2-r20.aarch64",
                  "product_id": "alt-nodejs16-16.20.2-r20.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16@16.20.2-r20?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-npm-16.20.2-r20.aarch64",
                "product": {
                  "name": "alt-nodejs16-npm-16.20.2-r20.aarch64",
                  "product_id": "alt-nodejs16-npm-16.20.2-r20.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-npm@16.20.2-r20?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-doc-16.20.2-r20.aarch64",
                "product": {
                  "name": "alt-nodejs16-doc-16.20.2-r20.aarch64",
                  "product_id": "alt-nodejs16-doc-16.20.2-r20.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-doc@16.20.2-r20?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-npm-18.20.8-r17.aarch64",
                "product": {
                  "name": "alt-nodejs18-npm-18.20.8-r17.aarch64",
                  "product_id": "alt-nodejs18-npm-18.20.8-r17.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-npm@18.20.8-r17?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-dev-18.20.8-r17.aarch64",
                "product": {
                  "name": "alt-nodejs18-dev-18.20.8-r17.aarch64",
                  "product_id": "alt-nodejs18-dev-18.20.8-r17.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-dev@18.20.8-r17?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-doc-18.20.8-r17.aarch64",
                "product": {
                  "name": "alt-nodejs18-doc-18.20.8-r17.aarch64",
                  "product_id": "alt-nodejs18-doc-18.20.8-r17.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-doc@18.20.8-r17?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-18.20.8-r17.aarch64",
                "product": {
                  "name": "alt-nodejs18-18.20.8-r17.aarch64",
                  "product_id": "alt-nodejs18-18.20.8-r17.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18@18.20.8-r17?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-nodejs18-dev-18.20.8-r14.x86_64",
                "product": {
                  "name": "alt-nodejs18-dev-18.20.8-r14.x86_64",
                  "product_id": "alt-nodejs18-dev-18.20.8-r14.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-dev@18.20.8-r14?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-18.20.8-r14.x86_64",
                "product": {
                  "name": "alt-nodejs18-18.20.8-r14.x86_64",
                  "product_id": "alt-nodejs18-18.20.8-r14.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18@18.20.8-r14?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-doc-18.20.8-r14.x86_64",
                "product": {
                  "name": "alt-nodejs18-doc-18.20.8-r14.x86_64",
                  "product_id": "alt-nodejs18-doc-18.20.8-r14.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-doc@18.20.8-r14?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-npm-18.20.8-r14.x86_64",
                "product": {
                  "name": "alt-nodejs18-npm-18.20.8-r14.x86_64",
                  "product_id": "alt-nodejs18-npm-18.20.8-r14.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-npm@18.20.8-r14?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-doc-14.21.3-r25.x86_64",
                "product": {
                  "name": "alt-nodejs14-doc-14.21.3-r25.x86_64",
                  "product_id": "alt-nodejs14-doc-14.21.3-r25.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-doc@14.21.3-r25?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-dev-14.21.3-r25.x86_64",
                "product": {
                  "name": "alt-nodejs14-dev-14.21.3-r25.x86_64",
                  "product_id": "alt-nodejs14-dev-14.21.3-r25.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-dev@14.21.3-r25?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-npm-14.21.3-r25.x86_64",
                "product": {
                  "name": "alt-nodejs14-npm-14.21.3-r25.x86_64",
                  "product_id": "alt-nodejs14-npm-14.21.3-r25.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-npm@14.21.3-r25?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-14.21.3-r25.x86_64",
                "product": {
                  "name": "alt-nodejs14-14.21.3-r25.x86_64",
                  "product_id": "alt-nodejs14-14.21.3-r25.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14@14.21.3-r25?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-doc-23.11.1-r15.x86_64",
                "product": {
                  "name": "alt-nodejs23-doc-23.11.1-r15.x86_64",
                  "product_id": "alt-nodejs23-doc-23.11.1-r15.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-doc@23.11.1-r15?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-dev-23.11.1-r15.x86_64",
                "product": {
                  "name": "alt-nodejs23-dev-23.11.1-r15.x86_64",
                  "product_id": "alt-nodejs23-dev-23.11.1-r15.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-dev@23.11.1-r15?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-23.11.1-r15.x86_64",
                "product": {
                  "name": "alt-nodejs23-23.11.1-r15.x86_64",
                  "product_id": "alt-nodejs23-23.11.1-r15.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23@23.11.1-r15?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-npm-23.11.1-r15.x86_64",
                "product": {
                  "name": "alt-nodejs23-npm-23.11.1-r15.x86_64",
                  "product_id": "alt-nodejs23-npm-23.11.1-r15.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-npm@23.11.1-r15?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-dev-16.20.2-r20.x86_64",
                "product": {
                  "name": "alt-nodejs16-dev-16.20.2-r20.x86_64",
                  "product_id": "alt-nodejs16-dev-16.20.2-r20.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-dev@16.20.2-r20?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-16.20.2-r20.x86_64",
                "product": {
                  "name": "alt-nodejs16-16.20.2-r20.x86_64",
                  "product_id": "alt-nodejs16-16.20.2-r20.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16@16.20.2-r20?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-npm-16.20.2-r20.x86_64",
                "product": {
                  "name": "alt-nodejs16-npm-16.20.2-r20.x86_64",
                  "product_id": "alt-nodejs16-npm-16.20.2-r20.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-npm@16.20.2-r20?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-doc-16.20.2-r20.x86_64",
                "product": {
                  "name": "alt-nodejs16-doc-16.20.2-r20.x86_64",
                  "product_id": "alt-nodejs16-doc-16.20.2-r20.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-doc@16.20.2-r20?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-npm-18.20.8-r17.x86_64",
                "product": {
                  "name": "alt-nodejs18-npm-18.20.8-r17.x86_64",
                  "product_id": "alt-nodejs18-npm-18.20.8-r17.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-npm@18.20.8-r17?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-dev-18.20.8-r17.x86_64",
                "product": {
                  "name": "alt-nodejs18-dev-18.20.8-r17.x86_64",
                  "product_id": "alt-nodejs18-dev-18.20.8-r17.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-dev@18.20.8-r17?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-doc-18.20.8-r17.x86_64",
                "product": {
                  "name": "alt-nodejs18-doc-18.20.8-r17.x86_64",
                  "product_id": "alt-nodejs18-doc-18.20.8-r17.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-doc@18.20.8-r17?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-18.20.8-r17.x86_64",
                "product": {
                  "name": "alt-nodejs18-18.20.8-r17.x86_64",
                  "product_id": "alt-nodejs18-18.20.8-r17.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18@18.20.8-r17?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-dev-18.20.8-r14.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.aarch64"
        },
        "product_reference": "alt-nodejs18-dev-18.20.8-r14.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-dev-18.20.8-r14.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.x86_64"
        },
        "product_reference": "alt-nodejs18-dev-18.20.8-r14.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-18.20.8-r14.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.aarch64"
        },
        "product_reference": "alt-nodejs18-18.20.8-r14.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-18.20.8-r14.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.x86_64"
        },
        "product_reference": "alt-nodejs18-18.20.8-r14.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-doc-18.20.8-r14.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.x86_64"
        },
        "product_reference": "alt-nodejs18-doc-18.20.8-r14.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-doc-18.20.8-r14.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.aarch64"
        },
        "product_reference": "alt-nodejs18-doc-18.20.8-r14.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-npm-18.20.8-r14.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.aarch64"
        },
        "product_reference": "alt-nodejs18-npm-18.20.8-r14.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-npm-18.20.8-r14.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.x86_64"
        },
        "product_reference": "alt-nodejs18-npm-18.20.8-r14.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-doc-14.21.3-r25.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.aarch64"
        },
        "product_reference": "alt-nodejs14-doc-14.21.3-r25.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-doc-14.21.3-r25.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.x86_64"
        },
        "product_reference": "alt-nodejs14-doc-14.21.3-r25.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-dev-14.21.3-r25.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.x86_64"
        },
        "product_reference": "alt-nodejs14-dev-14.21.3-r25.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-dev-14.21.3-r25.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.aarch64"
        },
        "product_reference": "alt-nodejs14-dev-14.21.3-r25.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-npm-14.21.3-r25.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.aarch64"
        },
        "product_reference": "alt-nodejs14-npm-14.21.3-r25.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-npm-14.21.3-r25.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.x86_64"
        },
        "product_reference": "alt-nodejs14-npm-14.21.3-r25.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-14.21.3-r25.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.x86_64"
        },
        "product_reference": "alt-nodejs14-14.21.3-r25.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-14.21.3-r25.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.aarch64"
        },
        "product_reference": "alt-nodejs14-14.21.3-r25.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-doc-23.11.1-r15.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.aarch64"
        },
        "product_reference": "alt-nodejs23-doc-23.11.1-r15.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-doc-23.11.1-r15.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.x86_64"
        },
        "product_reference": "alt-nodejs23-doc-23.11.1-r15.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-dev-23.11.1-r15.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.x86_64"
        },
        "product_reference": "alt-nodejs23-dev-23.11.1-r15.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-dev-23.11.1-r15.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.aarch64"
        },
        "product_reference": "alt-nodejs23-dev-23.11.1-r15.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-23.11.1-r15.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.x86_64"
        },
        "product_reference": "alt-nodejs23-23.11.1-r15.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-23.11.1-r15.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.aarch64"
        },
        "product_reference": "alt-nodejs23-23.11.1-r15.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-npm-23.11.1-r15.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.aarch64"
        },
        "product_reference": "alt-nodejs23-npm-23.11.1-r15.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-npm-23.11.1-r15.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.x86_64"
        },
        "product_reference": "alt-nodejs23-npm-23.11.1-r15.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-dev-16.20.2-r20.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.aarch64"
        },
        "product_reference": "alt-nodejs16-dev-16.20.2-r20.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-dev-16.20.2-r20.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.x86_64"
        },
        "product_reference": "alt-nodejs16-dev-16.20.2-r20.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-16.20.2-r20.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.aarch64"
        },
        "product_reference": "alt-nodejs16-16.20.2-r20.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-16.20.2-r20.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.x86_64"
        },
        "product_reference": "alt-nodejs16-16.20.2-r20.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-npm-16.20.2-r20.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.aarch64"
        },
        "product_reference": "alt-nodejs16-npm-16.20.2-r20.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-npm-16.20.2-r20.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.x86_64"
        },
        "product_reference": "alt-nodejs16-npm-16.20.2-r20.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-doc-16.20.2-r20.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.x86_64"
        },
        "product_reference": "alt-nodejs16-doc-16.20.2-r20.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-doc-16.20.2-r20.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.aarch64"
        },
        "product_reference": "alt-nodejs16-doc-16.20.2-r20.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-npm-18.20.8-r17.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.x86_64"
        },
        "product_reference": "alt-nodejs18-npm-18.20.8-r17.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-npm-18.20.8-r17.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.aarch64"
        },
        "product_reference": "alt-nodejs18-npm-18.20.8-r17.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-dev-18.20.8-r17.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.aarch64"
        },
        "product_reference": "alt-nodejs18-dev-18.20.8-r17.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-dev-18.20.8-r17.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.x86_64"
        },
        "product_reference": "alt-nodejs18-dev-18.20.8-r17.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-doc-18.20.8-r17.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.aarch64"
        },
        "product_reference": "alt-nodejs18-doc-18.20.8-r17.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-doc-18.20.8-r17.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.x86_64"
        },
        "product_reference": "alt-nodejs18-doc-18.20.8-r17.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-18.20.8-r17.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.x86_64"
        },
        "product_reference": "alt-nodejs18-18.20.8-r17.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-18.20.8-r17.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.aarch64"
        },
        "product_reference": "alt-nodejs18-18.20.8-r17.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2018-7167",
      "cwe": {
        "id": "CWE-119",
        "name": "Improper Restriction of Operations within the Bounds of a Memory Buffer"
      },
      "notes": [
        {
          "category": "description",
          "text": "Calling Buffer.fill() or Buffer.alloc() with some parameters can lead to a hang which could result in a Denial of Service. In order to address this vulnerability, the implementations of Buffer.alloc() and Buffer.fill() were updated so that they zero fill instead of hanging in these cases. All versions of Node.js 6.x (LTS \"Boron\"), 8.x (LTS \"Carbon\"), and 9.x are vulnerable. All versions of Node.js 10.x (Current) are NOT vulnerable.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        },
        {
          "category": "other",
          "text": "TuxCare has assessed that this vulnerability does not impact any currently supported TuxCare products. This evaluation may change as new information becomes available. For additional details regarding this vulnerability and affected products, refer to the provided references.",
          "title": "Statement"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.aarch64",
          "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.x86_64",
          "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.aarch64",
          "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.x86_64",
          "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.aarch64",
          "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.x86_64",
          "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.aarch64",
          "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.x86_64",
          "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.aarch64",
          "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.x86_64",
          "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.aarch64",
          "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.x86_64",
          "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.aarch64",
          "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.x86_64",
          "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.aarch64",
          "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.x86_64",
          "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.aarch64",
          "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.x86_64",
          "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.aarch64",
          "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.x86_64",
          "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.aarch64",
          "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.x86_64",
          "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.aarch64",
          "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-lang/cve/CVE-2018-7167"
        },
        {
          "category": "external",
          "summary": "http://www.securityfocus.com/bid/106363",
          "url": "http://www.securityfocus.com/bid/106363"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/",
          "url": "https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202003-48",
          "url": "https://security.gentoo.org/glsa/202003-48"
        }
      ],
      "release_date": "2018-06-13T16:29:00Z",
      "scores": [
        {
          "cvss_v2": {
            "accessComplexity": "LOW",
            "accessVector": "NETWORK",
            "authentication": "NONE",
            "availabilityImpact": "PARTIAL",
            "baseScore": 5.0,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
            "version": "2.0"
          },
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        },
        {
          "category": "impact",
          "date": "2026-07-29T07:48:13.650381Z",
          "details": "Already fixed\n\nalt-nodejs18 18.20.8: ALREADY FIXED — fix-present: same guard at `src/node_buffer.cc:738-739`, verified by clean reverse-apply of the guard-adding hunk of nodejs/node@1e802539b2.\n\nPlatform in scope: alpinelinux3.24 (alt-nodejs18 18.20.8). No sibling precedent existed for this CVE at this version anywhere in ELSLANG; assessed from the shipped source and build configuration of alt-nodejs18, not from NVD version ranges.\n\nEvidence\n### What ships and what the CVE touches\n- Vulnerable code is Node's **own C++ core**: `src/node_buffer.cc`, function `Fill()` — statically compiled into the `node` binary. It is **not** in `deps/openssl`, `deps/nghttp2`, `deps/zlib`, `deps/cares`, `deps/llhttp`, `deps/brotli` or any system library, so no `--shared-*` flag can move it out of the package. All four packages unambiguously ship this code and are judged on it (basis: **fix-present**, not not-shipped).\n- Linkage recorded for completeness from `APKBUILD` (Alpine build, `alpinelinux3.23` / `alpinelinux3.24`), **all irrelevant to this CVE**:\n  - `alt-nodejs14/APKBUILD:166-170` — `--shared-zlib --shared-openssl --shared-openssl-includes=/opt/alt/openssl11/include --shared-openssl-libpath=/opt/alt/openssl11/lib --with-intl=system-icu` → links **alt-openssl11 (1.1.1w)**.\n  - `alt-nodejs16/APKBUILD:172-175`, `alt-nodejs18/APKBUILD:149-152`, `alt-nodejs23/APKBUILD:134-137` — `--shared-openssl --shared-zlib --openssl-use-def-ca-store` with `openssl-dev` makedepend → link **Alpine system libssl3/libcrypto3 (OpenSSL 3.5.x)**. (Linkage audit per ELS-2268.)\n  - No `--shared-nghttp2`, `--shared-cares`, `--shared-http-parser`, `--shared-brotli` in any configure line → those remain **bundled**; none implements `Buffer#fill`, so no transitive carrier exists for this flaw. This CVE is **not transitive** — the flaw's home is Node core itself.\n\n### Upstream fix commit + first release containing it\n- **The commit our tree relies on:** `nodejs/node@1e802539b2811f5090281cfc8041f21120c2c3c6` — \"buffer: throw when filling with empty buffers\", PR [#18129](https://github.com/nodejs/node/pull/18129), fixes issue [#18128](https://github.com/nodejs/node/issues/18128) (the same infinite loop), landed 2018-01-17 on `master` as a semver-major behaviour change. It relocates the `str_length == 0` → `Set(-1)` guard from inside the string branch to **after** the `start_fill:` label, which is what makes the zero-length `Buffer`/`TypedArray` path (`Buffer::HasInstance(args[1])` → `str_length = 0` → `goto start_fill`) hit a guard. **First release containing it: v10.0.0.**\n- **The separate 6.x/8.x/9.x CVE backports (different mechanism):** `nodejs/node@555696df51012ff84ccf1378a38bcedb3ab98b52` → **v6.14.3**, and `nodejs/node@25c5111ca40bf55dd1b23caa838b20745356d936` → **v8.11.3 / v9.11.2**. Both add `if (in_there == 0) { memset(ts_obj_data + start, 0, fill_length); return; }` (zero-fill). Our trees do **not** contain `in_there == 0` and do not need to — the earlier `str_length == 0` guard returns before `in_there` is ever computed.\n- Upstream advisory ([Node.js June 2018 Security Releases](https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/)): \"All versions of Node.js 6.x … 8.x … 9.x are vulnerable. **All versions of Node.js 10.x (Current) are NOT vulnerable.**\" Our lines (14/16/18/23) all descend from the 10.x line.\n\n### Upstream tag survey (substitute for `git tag --contains`; no local clone available)\n`src/node_buffer.cc` fetched at each tag and inspected:\n\n| Tag | `str_length == 0` guard after `start_fill:` | `in_there == 0` zero-fill (6/8/9 CVE backport) |\n|-----|-----|-----|\n| v9.0.0 | no | no |",
          "product_ids": [
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.x86_64"
          ]
        },
        {
          "category": "impact",
          "date": "2026-07-29T07:48:10.441329Z",
          "details": "Already fixed\n\nalt-nodejs14 14.21.3: ALREADY FIXED — fix-present: shipped `src/node_buffer.cc` carries the `str_length == 0` guard (lines 641-642) after `start_fill:`, so a zero-length Buffer/TypedArray filler returns -1 and throws instead of entering the non-advancing doubling loop.\n\nPlatform in scope: alpinelinux3.24 (alt-nodejs14 14.21.3). No sibling precedent existed for this CVE at this version anywhere in ELSLANG; assessed from the shipped source and build configuration of alt-nodejs14, not from NVD version ranges.\n\nEvidence\n### What ships and what the CVE touches\n- Vulnerable code is Node's **own C++ core**: `src/node_buffer.cc`, function `Fill()` — statically compiled into the `node` binary. It is **not** in `deps/openssl`, `deps/nghttp2`, `deps/zlib`, `deps/cares`, `deps/llhttp`, `deps/brotli` or any system library, so no `--shared-*` flag can move it out of the package. All four packages unambiguously ship this code and are judged on it (basis: **fix-present**, not not-shipped).\n- Linkage recorded for completeness from `APKBUILD` (Alpine build, `alpinelinux3.23` / `alpinelinux3.24`), **all irrelevant to this CVE**:\n  - `alt-nodejs14/APKBUILD:166-170` — `--shared-zlib --shared-openssl --shared-openssl-includes=/opt/alt/openssl11/include --shared-openssl-libpath=/opt/alt/openssl11/lib --with-intl=system-icu` → links **alt-openssl11 (1.1.1w)**.\n  - `alt-nodejs16/APKBUILD:172-175`, `alt-nodejs18/APKBUILD:149-152`, `alt-nodejs23/APKBUILD:134-137` — `--shared-openssl --shared-zlib --openssl-use-def-ca-store` with `openssl-dev` makedepend → link **Alpine system libssl3/libcrypto3 (OpenSSL 3.5.x)**. (Linkage audit per ELS-2268.)\n  - No `--shared-nghttp2`, `--shared-cares`, `--shared-http-parser`, `--shared-brotli` in any configure line → those remain **bundled**; none implements `Buffer#fill`, so no transitive carrier exists for this flaw. This CVE is **not transitive** — the flaw's home is Node core itself.\n\n### Upstream fix commit + first release containing it\n- **The commit our tree relies on:** `nodejs/node@1e802539b2811f5090281cfc8041f21120c2c3c6` — \"buffer: throw when filling with empty buffers\", PR [#18129](https://github.com/nodejs/node/pull/18129), fixes issue [#18128](https://github.com/nodejs/node/issues/18128) (the same infinite loop), landed 2018-01-17 on `master` as a semver-major behaviour change. It relocates the `str_length == 0` → `Set(-1)` guard from inside the string branch to **after** the `start_fill:` label, which is what makes the zero-length `Buffer`/`TypedArray` path (`Buffer::HasInstance(args[1])` → `str_length = 0` → `goto start_fill`) hit a guard. **First release containing it: v10.0.0.**\n- **The separate 6.x/8.x/9.x CVE backports (different mechanism):** `nodejs/node@555696df51012ff84ccf1378a38bcedb3ab98b52` → **v6.14.3**, and `nodejs/node@25c5111ca40bf55dd1b23caa838b20745356d936` → **v8.11.3 / v9.11.2**. Both add `if (in_there == 0) { memset(ts_obj_data + start, 0, fill_length); return; }` (zero-fill). Our trees do **not** contain `in_there == 0` and do not need to — the earlier `str_length == 0` guard returns before `in_there` is ever computed.\n- Upstream advisory ([Node.js June 2018 Security Releases](https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/)): \"All versions of Node.js 6.x … 8.x … 9.x are vulnerable. **All versions of Node.js 10.x (Current) are NOT vulnerable.**\" Our lines (14/16/18/23) all descend from the 10.x line.\n\n### Upstream tag survey (substitute for `git tag --contains`; no local clone available)\n`src/node_buffer.cc` fetched at each tag and inspected:\n\n| Tag | `str_length == 0` guard after `start_fill:` | `in_there == 0` zero-fill (6/8/9 CVE backport) |\n|-----|-----|-----|\n| v9.0.0 | no | no |",
          "product_ids": [
            "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.x86_64"
          ]
        },
        {
          "category": "impact",
          "date": "2026-07-29T07:48:07.233521Z",
          "details": "Already fixed\n\nalt-nodejs23 23.11.1: ALREADY FIXED — fix-present: same guard at `src/node_buffer.cc:680-681`, verified by clean reverse-apply of the guard-adding hunk of nodejs/node@1e802539b2.\n\nPlatform in scope: alpinelinux3.24 (alt-nodejs23 23.11.1). No sibling precedent existed for this CVE at this version anywhere in ELSLANG; assessed from the shipped source and build configuration of alt-nodejs23, not from NVD version ranges.\n\nEvidence\n### What ships and what the CVE touches\n- Vulnerable code is Node's **own C++ core**: `src/node_buffer.cc`, function `Fill()` — statically compiled into the `node` binary. It is **not** in `deps/openssl`, `deps/nghttp2`, `deps/zlib`, `deps/cares`, `deps/llhttp`, `deps/brotli` or any system library, so no `--shared-*` flag can move it out of the package. All four packages unambiguously ship this code and are judged on it (basis: **fix-present**, not not-shipped).\n- Linkage recorded for completeness from `APKBUILD` (Alpine build, `alpinelinux3.23` / `alpinelinux3.24`), **all irrelevant to this CVE**:\n  - `alt-nodejs14/APKBUILD:166-170` — `--shared-zlib --shared-openssl --shared-openssl-includes=/opt/alt/openssl11/include --shared-openssl-libpath=/opt/alt/openssl11/lib --with-intl=system-icu` → links **alt-openssl11 (1.1.1w)**.\n  - `alt-nodejs16/APKBUILD:172-175`, `alt-nodejs18/APKBUILD:149-152`, `alt-nodejs23/APKBUILD:134-137` — `--shared-openssl --shared-zlib --openssl-use-def-ca-store` with `openssl-dev` makedepend → link **Alpine system libssl3/libcrypto3 (OpenSSL 3.5.x)**. (Linkage audit per ELS-2268.)\n  - No `--shared-nghttp2`, `--shared-cares`, `--shared-http-parser`, `--shared-brotli` in any configure line → those remain **bundled**; none implements `Buffer#fill`, so no transitive carrier exists for this flaw. This CVE is **not transitive** — the flaw's home is Node core itself.\n\n### Upstream fix commit + first release containing it\n- **The commit our tree relies on:** `nodejs/node@1e802539b2811f5090281cfc8041f21120c2c3c6` — \"buffer: throw when filling with empty buffers\", PR [#18129](https://github.com/nodejs/node/pull/18129), fixes issue [#18128](https://github.com/nodejs/node/issues/18128) (the same infinite loop), landed 2018-01-17 on `master` as a semver-major behaviour change. It relocates the `str_length == 0` → `Set(-1)` guard from inside the string branch to **after** the `start_fill:` label, which is what makes the zero-length `Buffer`/`TypedArray` path (`Buffer::HasInstance(args[1])` → `str_length = 0` → `goto start_fill`) hit a guard. **First release containing it: v10.0.0.**\n- **The separate 6.x/8.x/9.x CVE backports (different mechanism):** `nodejs/node@555696df51012ff84ccf1378a38bcedb3ab98b52` → **v6.14.3**, and `nodejs/node@25c5111ca40bf55dd1b23caa838b20745356d936` → **v8.11.3 / v9.11.2**. Both add `if (in_there == 0) { memset(ts_obj_data + start, 0, fill_length); return; }` (zero-fill). Our trees do **not** contain `in_there == 0` and do not need to — the earlier `str_length == 0` guard returns before `in_there` is ever computed.\n- Upstream advisory ([Node.js June 2018 Security Releases](https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/)): \"All versions of Node.js 6.x … 8.x … 9.x are vulnerable. **All versions of Node.js 10.x (Current) are NOT vulnerable.**\" Our lines (14/16/18/23) all descend from the 10.x line.\n\n### Upstream tag survey (substitute for `git tag --contains`; no local clone available)\n`src/node_buffer.cc` fetched at each tag and inspected:\n\n| Tag | `str_length == 0` guard after `start_fill:` | `in_there == 0` zero-fill (6/8/9 CVE backport) |\n|-----|-----|-----|\n| v9.0.0 | no | no |",
          "product_ids": [
            "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.x86_64"
          ]
        },
        {
          "category": "impact",
          "date": "2026-07-29T07:47:58.813845Z",
          "details": "Already fixed\n\nalt-nodejs16 16.20.2: ALREADY FIXED — fix-present: same guard at `src/node_buffer.cc:684-685`, verified by clean reverse-apply of the guard-adding hunk of nodejs/node@1e802539b2.\n\nPlatform in scope: alpinelinux3.24 (alt-nodejs16 16.20.2). No sibling precedent existed for this CVE at this version anywhere in ELSLANG; assessed from the shipped source and build configuration of alt-nodejs16, not from NVD version ranges.\n\nEvidence\n### What ships and what the CVE touches\n- Vulnerable code is Node's **own C++ core**: `src/node_buffer.cc`, function `Fill()` — statically compiled into the `node` binary. It is **not** in `deps/openssl`, `deps/nghttp2`, `deps/zlib`, `deps/cares`, `deps/llhttp`, `deps/brotli` or any system library, so no `--shared-*` flag can move it out of the package. All four packages unambiguously ship this code and are judged on it (basis: **fix-present**, not not-shipped).\n- Linkage recorded for completeness from `APKBUILD` (Alpine build, `alpinelinux3.23` / `alpinelinux3.24`), **all irrelevant to this CVE**:\n  - `alt-nodejs14/APKBUILD:166-170` — `--shared-zlib --shared-openssl --shared-openssl-includes=/opt/alt/openssl11/include --shared-openssl-libpath=/opt/alt/openssl11/lib --with-intl=system-icu` → links **alt-openssl11 (1.1.1w)**.\n  - `alt-nodejs16/APKBUILD:172-175`, `alt-nodejs18/APKBUILD:149-152`, `alt-nodejs23/APKBUILD:134-137` — `--shared-openssl --shared-zlib --openssl-use-def-ca-store` with `openssl-dev` makedepend → link **Alpine system libssl3/libcrypto3 (OpenSSL 3.5.x)**. (Linkage audit per ELS-2268.)\n  - No `--shared-nghttp2`, `--shared-cares`, `--shared-http-parser`, `--shared-brotli` in any configure line → those remain **bundled**; none implements `Buffer#fill`, so no transitive carrier exists for this flaw. This CVE is **not transitive** — the flaw's home is Node core itself.\n\n### Upstream fix commit + first release containing it\n- **The commit our tree relies on:** `nodejs/node@1e802539b2811f5090281cfc8041f21120c2c3c6` — \"buffer: throw when filling with empty buffers\", PR [#18129](https://github.com/nodejs/node/pull/18129), fixes issue [#18128](https://github.com/nodejs/node/issues/18128) (the same infinite loop), landed 2018-01-17 on `master` as a semver-major behaviour change. It relocates the `str_length == 0` → `Set(-1)` guard from inside the string branch to **after** the `start_fill:` label, which is what makes the zero-length `Buffer`/`TypedArray` path (`Buffer::HasInstance(args[1])` → `str_length = 0` → `goto start_fill`) hit a guard. **First release containing it: v10.0.0.**\n- **The separate 6.x/8.x/9.x CVE backports (different mechanism):** `nodejs/node@555696df51012ff84ccf1378a38bcedb3ab98b52` → **v6.14.3**, and `nodejs/node@25c5111ca40bf55dd1b23caa838b20745356d936` → **v8.11.3 / v9.11.2**. Both add `if (in_there == 0) { memset(ts_obj_data + start, 0, fill_length); return; }` (zero-fill). Our trees do **not** contain `in_there == 0` and do not need to — the earlier `str_length == 0` guard returns before `in_there` is ever computed.\n- Upstream advisory ([Node.js June 2018 Security Releases](https://nodejs.org/en/blog/vulnerability/june-2018-security-releases/)): \"All versions of Node.js 6.x … 8.x … 9.x are vulnerable. **All versions of Node.js 10.x (Current) are NOT vulnerable.**\" Our lines (14/16/18/23) all descend from the 10.x line.\n\n### Upstream tag survey (substitute for `git tag --contains`; no local clone available)\n`src/node_buffer.cc` fetched at each tag and inspected:\n\n| Tag | `str_length == 0` guard after `start_fill:` | `in_there == 0` zero-fill (6/8/9 CVE backport) |\n|-----|-----|-----|\n| v9.0.0 | no | no |",
          "product_ids": [
            "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.x86_64"
          ]
        }
      ]
    }
  ]
}