{
  "document": {
    "aggregate_severity": {
      "text": "High"
    },
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_alt_nodejs/alpinelinux3.24/vex/2021/cve-2021-32050-els_alt_nodejs-alpinelinux3_24.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-31T12:46:35Z",
      "generator": {
        "date": "2026-07-31T12:46:34Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2021-32050-ELS_ALT_NODEJS-ALPINELINUX3.24",
      "initial_release_date": "2021-01-01T00:00:00Z",
      "revision_history": [
        {
          "date": "2021-01-01T00:00:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-28T12:26:02Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-29T08:27:08Z",
          "number": "3",
          "summary": "Update document"
        },
        {
          "date": "2026-07-31T12:46:35Z",
          "number": "4",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "4"
    },
    "title": "Security update on CVE-2021-32050"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Alpine Linux 3.24",
                "product": {
                  "name": "Alpine Linux 3.24",
                  "product_id": "Alpine-Linux-3.24",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:alpinelinux:alpine_linux:3.24:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Alpine Linux"
          }
        ],
        "category": "vendor",
        "name": "Alpine Linux"
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-nodejs18-dev-18.20.8-r14.aarch64",
                "product": {
                  "name": "alt-nodejs18-dev-18.20.8-r14.aarch64",
                  "product_id": "alt-nodejs18-dev-18.20.8-r14.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-dev@18.20.8-r14?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-18.20.8-r14.aarch64",
                "product": {
                  "name": "alt-nodejs18-18.20.8-r14.aarch64",
                  "product_id": "alt-nodejs18-18.20.8-r14.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18@18.20.8-r14?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-doc-18.20.8-r14.aarch64",
                "product": {
                  "name": "alt-nodejs18-doc-18.20.8-r14.aarch64",
                  "product_id": "alt-nodejs18-doc-18.20.8-r14.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-doc@18.20.8-r14?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-npm-18.20.8-r14.aarch64",
                "product": {
                  "name": "alt-nodejs18-npm-18.20.8-r14.aarch64",
                  "product_id": "alt-nodejs18-npm-18.20.8-r14.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-npm@18.20.8-r14?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-doc-14.21.3-r25.aarch64",
                "product": {
                  "name": "alt-nodejs14-doc-14.21.3-r25.aarch64",
                  "product_id": "alt-nodejs14-doc-14.21.3-r25.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-doc@14.21.3-r25?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-dev-14.21.3-r25.aarch64",
                "product": {
                  "name": "alt-nodejs14-dev-14.21.3-r25.aarch64",
                  "product_id": "alt-nodejs14-dev-14.21.3-r25.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-dev@14.21.3-r25?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-npm-14.21.3-r25.aarch64",
                "product": {
                  "name": "alt-nodejs14-npm-14.21.3-r25.aarch64",
                  "product_id": "alt-nodejs14-npm-14.21.3-r25.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-npm@14.21.3-r25?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-14.21.3-r25.aarch64",
                "product": {
                  "name": "alt-nodejs14-14.21.3-r25.aarch64",
                  "product_id": "alt-nodejs14-14.21.3-r25.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14@14.21.3-r25?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-doc-23.11.1-r15.aarch64",
                "product": {
                  "name": "alt-nodejs23-doc-23.11.1-r15.aarch64",
                  "product_id": "alt-nodejs23-doc-23.11.1-r15.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-doc@23.11.1-r15?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-dev-23.11.1-r15.aarch64",
                "product": {
                  "name": "alt-nodejs23-dev-23.11.1-r15.aarch64",
                  "product_id": "alt-nodejs23-dev-23.11.1-r15.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-dev@23.11.1-r15?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-23.11.1-r15.aarch64",
                "product": {
                  "name": "alt-nodejs23-23.11.1-r15.aarch64",
                  "product_id": "alt-nodejs23-23.11.1-r15.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23@23.11.1-r15?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-npm-23.11.1-r15.aarch64",
                "product": {
                  "name": "alt-nodejs23-npm-23.11.1-r15.aarch64",
                  "product_id": "alt-nodejs23-npm-23.11.1-r15.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-npm@23.11.1-r15?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-dev-16.20.2-r20.aarch64",
                "product": {
                  "name": "alt-nodejs16-dev-16.20.2-r20.aarch64",
                  "product_id": "alt-nodejs16-dev-16.20.2-r20.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-dev@16.20.2-r20?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-16.20.2-r20.aarch64",
                "product": {
                  "name": "alt-nodejs16-16.20.2-r20.aarch64",
                  "product_id": "alt-nodejs16-16.20.2-r20.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16@16.20.2-r20?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-npm-16.20.2-r20.aarch64",
                "product": {
                  "name": "alt-nodejs16-npm-16.20.2-r20.aarch64",
                  "product_id": "alt-nodejs16-npm-16.20.2-r20.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-npm@16.20.2-r20?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-doc-16.20.2-r20.aarch64",
                "product": {
                  "name": "alt-nodejs16-doc-16.20.2-r20.aarch64",
                  "product_id": "alt-nodejs16-doc-16.20.2-r20.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-doc@16.20.2-r20?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-npm-18.20.8-r17.aarch64",
                "product": {
                  "name": "alt-nodejs18-npm-18.20.8-r17.aarch64",
                  "product_id": "alt-nodejs18-npm-18.20.8-r17.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-npm@18.20.8-r17?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-dev-18.20.8-r17.aarch64",
                "product": {
                  "name": "alt-nodejs18-dev-18.20.8-r17.aarch64",
                  "product_id": "alt-nodejs18-dev-18.20.8-r17.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-dev@18.20.8-r17?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-doc-18.20.8-r17.aarch64",
                "product": {
                  "name": "alt-nodejs18-doc-18.20.8-r17.aarch64",
                  "product_id": "alt-nodejs18-doc-18.20.8-r17.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-doc@18.20.8-r17?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-18.20.8-r17.aarch64",
                "product": {
                  "name": "alt-nodejs18-18.20.8-r17.aarch64",
                  "product_id": "alt-nodejs18-18.20.8-r17.aarch64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18@18.20.8-r17?arch=aarch64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "aarch64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-nodejs18-dev-18.20.8-r14.x86_64",
                "product": {
                  "name": "alt-nodejs18-dev-18.20.8-r14.x86_64",
                  "product_id": "alt-nodejs18-dev-18.20.8-r14.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-dev@18.20.8-r14?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-18.20.8-r14.x86_64",
                "product": {
                  "name": "alt-nodejs18-18.20.8-r14.x86_64",
                  "product_id": "alt-nodejs18-18.20.8-r14.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18@18.20.8-r14?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-doc-18.20.8-r14.x86_64",
                "product": {
                  "name": "alt-nodejs18-doc-18.20.8-r14.x86_64",
                  "product_id": "alt-nodejs18-doc-18.20.8-r14.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-doc@18.20.8-r14?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-npm-18.20.8-r14.x86_64",
                "product": {
                  "name": "alt-nodejs18-npm-18.20.8-r14.x86_64",
                  "product_id": "alt-nodejs18-npm-18.20.8-r14.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-npm@18.20.8-r14?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-doc-14.21.3-r25.x86_64",
                "product": {
                  "name": "alt-nodejs14-doc-14.21.3-r25.x86_64",
                  "product_id": "alt-nodejs14-doc-14.21.3-r25.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-doc@14.21.3-r25?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-dev-14.21.3-r25.x86_64",
                "product": {
                  "name": "alt-nodejs14-dev-14.21.3-r25.x86_64",
                  "product_id": "alt-nodejs14-dev-14.21.3-r25.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-dev@14.21.3-r25?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-npm-14.21.3-r25.x86_64",
                "product": {
                  "name": "alt-nodejs14-npm-14.21.3-r25.x86_64",
                  "product_id": "alt-nodejs14-npm-14.21.3-r25.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14-npm@14.21.3-r25?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs14-14.21.3-r25.x86_64",
                "product": {
                  "name": "alt-nodejs14-14.21.3-r25.x86_64",
                  "product_id": "alt-nodejs14-14.21.3-r25.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs14@14.21.3-r25?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-doc-23.11.1-r15.x86_64",
                "product": {
                  "name": "alt-nodejs23-doc-23.11.1-r15.x86_64",
                  "product_id": "alt-nodejs23-doc-23.11.1-r15.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-doc@23.11.1-r15?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-dev-23.11.1-r15.x86_64",
                "product": {
                  "name": "alt-nodejs23-dev-23.11.1-r15.x86_64",
                  "product_id": "alt-nodejs23-dev-23.11.1-r15.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-dev@23.11.1-r15?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-23.11.1-r15.x86_64",
                "product": {
                  "name": "alt-nodejs23-23.11.1-r15.x86_64",
                  "product_id": "alt-nodejs23-23.11.1-r15.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23@23.11.1-r15?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs23-npm-23.11.1-r15.x86_64",
                "product": {
                  "name": "alt-nodejs23-npm-23.11.1-r15.x86_64",
                  "product_id": "alt-nodejs23-npm-23.11.1-r15.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs23-npm@23.11.1-r15?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-dev-16.20.2-r20.x86_64",
                "product": {
                  "name": "alt-nodejs16-dev-16.20.2-r20.x86_64",
                  "product_id": "alt-nodejs16-dev-16.20.2-r20.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-dev@16.20.2-r20?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-16.20.2-r20.x86_64",
                "product": {
                  "name": "alt-nodejs16-16.20.2-r20.x86_64",
                  "product_id": "alt-nodejs16-16.20.2-r20.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16@16.20.2-r20?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-npm-16.20.2-r20.x86_64",
                "product": {
                  "name": "alt-nodejs16-npm-16.20.2-r20.x86_64",
                  "product_id": "alt-nodejs16-npm-16.20.2-r20.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-npm@16.20.2-r20?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs16-doc-16.20.2-r20.x86_64",
                "product": {
                  "name": "alt-nodejs16-doc-16.20.2-r20.x86_64",
                  "product_id": "alt-nodejs16-doc-16.20.2-r20.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs16-doc@16.20.2-r20?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-npm-18.20.8-r17.x86_64",
                "product": {
                  "name": "alt-nodejs18-npm-18.20.8-r17.x86_64",
                  "product_id": "alt-nodejs18-npm-18.20.8-r17.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-npm@18.20.8-r17?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-dev-18.20.8-r17.x86_64",
                "product": {
                  "name": "alt-nodejs18-dev-18.20.8-r17.x86_64",
                  "product_id": "alt-nodejs18-dev-18.20.8-r17.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-dev@18.20.8-r17?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-doc-18.20.8-r17.x86_64",
                "product": {
                  "name": "alt-nodejs18-doc-18.20.8-r17.x86_64",
                  "product_id": "alt-nodejs18-doc-18.20.8-r17.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18-doc@18.20.8-r17?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs18-18.20.8-r17.x86_64",
                "product": {
                  "name": "alt-nodejs18-18.20.8-r17.x86_64",
                  "product_id": "alt-nodejs18-18.20.8-r17.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:apk/tuxcare/alt-nodejs18@18.20.8-r17?arch=x86_64&os_name=alpine&os_version=3.24"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-dev-18.20.8-r14.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.aarch64"
        },
        "product_reference": "alt-nodejs18-dev-18.20.8-r14.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-dev-18.20.8-r14.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.x86_64"
        },
        "product_reference": "alt-nodejs18-dev-18.20.8-r14.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-18.20.8-r14.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.aarch64"
        },
        "product_reference": "alt-nodejs18-18.20.8-r14.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-18.20.8-r14.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.x86_64"
        },
        "product_reference": "alt-nodejs18-18.20.8-r14.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-doc-18.20.8-r14.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.x86_64"
        },
        "product_reference": "alt-nodejs18-doc-18.20.8-r14.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-doc-18.20.8-r14.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.aarch64"
        },
        "product_reference": "alt-nodejs18-doc-18.20.8-r14.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-npm-18.20.8-r14.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.aarch64"
        },
        "product_reference": "alt-nodejs18-npm-18.20.8-r14.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-npm-18.20.8-r14.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.x86_64"
        },
        "product_reference": "alt-nodejs18-npm-18.20.8-r14.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-doc-14.21.3-r25.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.aarch64"
        },
        "product_reference": "alt-nodejs14-doc-14.21.3-r25.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-doc-14.21.3-r25.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.x86_64"
        },
        "product_reference": "alt-nodejs14-doc-14.21.3-r25.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-dev-14.21.3-r25.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.x86_64"
        },
        "product_reference": "alt-nodejs14-dev-14.21.3-r25.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-dev-14.21.3-r25.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.aarch64"
        },
        "product_reference": "alt-nodejs14-dev-14.21.3-r25.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-npm-14.21.3-r25.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.aarch64"
        },
        "product_reference": "alt-nodejs14-npm-14.21.3-r25.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-npm-14.21.3-r25.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.x86_64"
        },
        "product_reference": "alt-nodejs14-npm-14.21.3-r25.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-14.21.3-r25.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.x86_64"
        },
        "product_reference": "alt-nodejs14-14.21.3-r25.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs14-14.21.3-r25.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.aarch64"
        },
        "product_reference": "alt-nodejs14-14.21.3-r25.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-doc-23.11.1-r15.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.aarch64"
        },
        "product_reference": "alt-nodejs23-doc-23.11.1-r15.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-doc-23.11.1-r15.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.x86_64"
        },
        "product_reference": "alt-nodejs23-doc-23.11.1-r15.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-dev-23.11.1-r15.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.x86_64"
        },
        "product_reference": "alt-nodejs23-dev-23.11.1-r15.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-dev-23.11.1-r15.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.aarch64"
        },
        "product_reference": "alt-nodejs23-dev-23.11.1-r15.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-23.11.1-r15.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.x86_64"
        },
        "product_reference": "alt-nodejs23-23.11.1-r15.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-23.11.1-r15.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.aarch64"
        },
        "product_reference": "alt-nodejs23-23.11.1-r15.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-npm-23.11.1-r15.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.aarch64"
        },
        "product_reference": "alt-nodejs23-npm-23.11.1-r15.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs23-npm-23.11.1-r15.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.x86_64"
        },
        "product_reference": "alt-nodejs23-npm-23.11.1-r15.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-dev-16.20.2-r20.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.aarch64"
        },
        "product_reference": "alt-nodejs16-dev-16.20.2-r20.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-dev-16.20.2-r20.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.x86_64"
        },
        "product_reference": "alt-nodejs16-dev-16.20.2-r20.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-16.20.2-r20.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.aarch64"
        },
        "product_reference": "alt-nodejs16-16.20.2-r20.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-16.20.2-r20.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.x86_64"
        },
        "product_reference": "alt-nodejs16-16.20.2-r20.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-npm-16.20.2-r20.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.aarch64"
        },
        "product_reference": "alt-nodejs16-npm-16.20.2-r20.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-npm-16.20.2-r20.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.x86_64"
        },
        "product_reference": "alt-nodejs16-npm-16.20.2-r20.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-doc-16.20.2-r20.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.x86_64"
        },
        "product_reference": "alt-nodejs16-doc-16.20.2-r20.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs16-doc-16.20.2-r20.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.aarch64"
        },
        "product_reference": "alt-nodejs16-doc-16.20.2-r20.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-npm-18.20.8-r17.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.x86_64"
        },
        "product_reference": "alt-nodejs18-npm-18.20.8-r17.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-npm-18.20.8-r17.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.aarch64"
        },
        "product_reference": "alt-nodejs18-npm-18.20.8-r17.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-dev-18.20.8-r17.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.aarch64"
        },
        "product_reference": "alt-nodejs18-dev-18.20.8-r17.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-dev-18.20.8-r17.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.x86_64"
        },
        "product_reference": "alt-nodejs18-dev-18.20.8-r17.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-doc-18.20.8-r17.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.aarch64"
        },
        "product_reference": "alt-nodejs18-doc-18.20.8-r17.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-doc-18.20.8-r17.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.x86_64"
        },
        "product_reference": "alt-nodejs18-doc-18.20.8-r17.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-18.20.8-r17.x86_64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.x86_64"
        },
        "product_reference": "alt-nodejs18-18.20.8-r17.x86_64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs18-18.20.8-r17.aarch64 as a component of Alpine Linux 3.24",
          "product_id": "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.aarch64"
        },
        "product_reference": "alt-nodejs18-18.20.8-r17.aarch64",
        "relates_to_product_reference": "Alpine-Linux-3.24"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-32050",
      "cwe": {
        "id": "CWE-200",
        "name": "Exposure of Sensitive Information to an Unauthorized Actor"
      },
      "notes": [
        {
          "category": "description",
          "text": "Some MongoDB Drivers may erroneously publish events containing authentication-related data to a command listener configured by an application. The published events may contain security-sensitive data when specific authentication-related commands are executed.\n\nWithout due care, an application may inadvertently expose this sensitive information, e.g., by writing it to a log file. This issue only arises if an application enables the command listener feature (this is not enabled by default).\n\nThis issue affects the MongoDB C Driver 1.0.0 prior to 1.17.7, MongoDB PHP Driver 1.0.0 prior to 1.9.2, MongoDB Swift Driver 1.0.0 prior to 1.1.1, MongoDB Node.js Driver 3.6 prior to 3.6.10, MongoDB Node.js Driver 4.0 prior to 4.17.0 and MongoDB Node.js Driver 5.0 prior to 5.8.0. This issue also affects users of the MongoDB C++ Driver dependent on the C driver 1.0.0 prior to 1.17.7 (C++ driver prior to 3.7.0).",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        },
        {
          "category": "other",
          "text": "TuxCare has assessed that this vulnerability does not impact any currently supported TuxCare products. This evaluation may change as new information becomes available. For additional details regarding this vulnerability and affected products, refer to the provided references.",
          "title": "Statement"
        }
      ],
      "product_status": {
        "known_not_affected": [
          "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.aarch64",
          "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.x86_64",
          "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.aarch64",
          "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.x86_64",
          "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.aarch64",
          "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.x86_64",
          "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.aarch64",
          "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.x86_64",
          "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.aarch64",
          "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.x86_64",
          "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.aarch64",
          "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.x86_64",
          "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.aarch64",
          "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.x86_64",
          "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.aarch64",
          "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.x86_64",
          "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.aarch64",
          "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.x86_64",
          "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.aarch64",
          "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.x86_64",
          "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.aarch64",
          "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.x86_64",
          "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.aarch64",
          "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.x86_64",
          "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.aarch64",
          "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-lang/cve/CVE-2021-32050"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/CDRIVER-3797",
          "url": "https://jira.mongodb.org/browse/CDRIVER-3797"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/CXX-2028",
          "url": "https://jira.mongodb.org/browse/CXX-2028"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/NODE-3356",
          "url": "https://jira.mongodb.org/browse/NODE-3356"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/PHPC-1869",
          "url": "https://jira.mongodb.org/browse/PHPC-1869"
        },
        {
          "category": "external",
          "summary": "https://jira.mongodb.org/browse/SWIFT-1229",
          "url": "https://jira.mongodb.org/browse/SWIFT-1229"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20231006-0001/",
          "url": "https://security.netapp.com/advisory/ntap-20231006-0001/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/05/msg00027.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/05/msg00027.html"
        }
      ],
      "release_date": "2023-08-29T16:15:00Z",
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        },
        {
          "category": "impact",
          "date": "2026-07-29T07:48:14.191554Z",
          "details": "Not vulnerable\n\nalt-nodejs18 18.20.8: NOT AFFECTED — same basis: MongoDB driver component absent from the shipped tree; `src/cmap/command_monitoring_events.ts` (the file the upstream fix touches) has no counterpart in Node.js.\n\nPlatform in scope: alpinelinux3.24 (alt-nodejs18 18.20.8). No sibling precedent existed for this CVE at this version anywhere in ELSLANG; assessed from the shipped source and build configuration of alt-nodejs18, not from NVD version ranges.\n\nEvidence\n### 1. The CVE is scoped to MongoDB drivers, not to the Node.js runtime\n- NVD CPE configuration for CVE-2021-32050 (`services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2021-32050`) lists **only** vendor `mongodb` products:\n  - `cpe:2.3:a:mongodb:c_driver` >=1.0.0 <1.17.7\n  - `cpe:2.3:a:mongodb:c\\+\\+` >=1.0.0 <1.17.7\n  - `cpe:2.3:a:mongodb:node.js` >=3.6 <3.6.10, >=4.0 <4.17.0, >=5.0 <5.8.0\n  - `cpe:2.3:a:mongodb:php_driver` >=1.0.0 <1.9.2\n  - `cpe:2.3:a:mongodb:swift_driver` >=1.0.0 <1.1.1\n  There is **no** `cpe:2.3:a:nodejs:node.js` entry. CNA is `cna@mongodb.com`.\n- **Root cause of the tickets:** the CPE product string is literally `node.js` (under vendor `mongodb`). A matcher that keys on the product string and ignores the vendor field maps it onto the `nodejs` source package. The affected ranges (3.6.x / 4.x / 5.x) are `mongodb` npm-driver versions and do not correspond to Node.js release lines at all.\n- **Alpine (platform-matching vendor, alpinelinux3.23/3.24):** `https://security.alpinelinux.org/vuln/CVE-2021-32050` returns `state = []` — **no Alpine source package is flagged as affected or fixed**. Its CPE-derived pseudo-packages are `c++`, `c_driver`, `node.js`, `php_driver`, `swift_driver` — all MongoDB products.\n- **Debian:** `security-tracker.debian.org/tracker/CVE-2021-32050` associates three source packages — `mongo-c-driver` (fixed 1.17.6-1+deb11u2 in bullseye), `php-mongodb`, `node-mongodb`. The `nodejs` source package is **not listed**. The Debian LTS announce referenced by NVD (`lists.debian.org/debian-lts-announce/2025/05/msg00027.html`) is for `mongo-c-driver`.\n- **Packages that actually carry the vulnerable code:** `mongo-c-driver` (+ mongo-cxx-driver), `php-mongodb` / PECL `mongodb` extension (relevant to alt-php, not here), the Swift driver, and the `mongodb` npm package. **None of these is shipped by any alt-nodejs package.**\n\n### 2. Upstream fix metadata (MongoDB Node.js driver)\n- Fix commit: `mongodb/node-mongodb-native@536e5ffbc941e8b99ad1c12c5239a688162a494e` — \"fix(NODE-3356): update redaction logic for command monitoring events (#2849)\", committed 2021-06-16.\n  https://github.com/mongodb/node-mongodb-native/commit/536e5ffbc941e8b99ad1c12c5239a688162a494e\n- Files changed: `src/cmap/command_monitoring_events.ts` (+10/-5), `test/functional/apm.test.js`.\n- Logic added: `HELLO_COMMANDS = {hello, ismaster, isMaster}` alongside `SENSITIVE_COMMANDS`; `maybeRedact()` now also redacts a hello/ismaster command when it carries `speculativeAuthenticate`.",
          "product_ids": [
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-dev-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-doc-18.20.8-r17.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r14.x86_64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.aarch64",
            "Alpine-Linux-3.24:alt-nodejs18-npm-18.20.8-r17.x86_64"
          ]
        },
        {
          "category": "impact",
          "date": "2026-07-29T07:48:11.847782Z",
          "details": "Not vulnerable\n\nalt-nodejs14 14.21.3: NOT AFFECTED — CVE-2021-32050 is a MongoDB *driver* flaw (`mongodb` npm package / mongo-c-driver / php-mongodb); the vulnerable component is not shipped or linked by this package, and the entire shipped tree (including the 356 packages bundled under `deps/npm`) contains zero MongoDB driver code.\n\nPlatform in scope: alpinelinux3.24 (alt-nodejs14 14.21.3). No sibling precedent existed for this CVE at this version anywhere in ELSLANG; assessed from the shipped source and build configuration of alt-nodejs14, not from NVD version ranges.\n\nEvidence\n### 1. The CVE is scoped to MongoDB drivers, not to the Node.js runtime\n- NVD CPE configuration for CVE-2021-32050 (`services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2021-32050`) lists **only** vendor `mongodb` products:\n  - `cpe:2.3:a:mongodb:c_driver` >=1.0.0 <1.17.7\n  - `cpe:2.3:a:mongodb:c\\+\\+` >=1.0.0 <1.17.7\n  - `cpe:2.3:a:mongodb:node.js` >=3.6 <3.6.10, >=4.0 <4.17.0, >=5.0 <5.8.0\n  - `cpe:2.3:a:mongodb:php_driver` >=1.0.0 <1.9.2\n  - `cpe:2.3:a:mongodb:swift_driver` >=1.0.0 <1.1.1\n  There is **no** `cpe:2.3:a:nodejs:node.js` entry. CNA is `cna@mongodb.com`.\n- **Root cause of the tickets:** the CPE product string is literally `node.js` (under vendor `mongodb`). A matcher that keys on the product string and ignores the vendor field maps it onto the `nodejs` source package. The affected ranges (3.6.x / 4.x / 5.x) are `mongodb` npm-driver versions and do not correspond to Node.js release lines at all.\n- **Alpine (platform-matching vendor, alpinelinux3.23/3.24):** `https://security.alpinelinux.org/vuln/CVE-2021-32050` returns `state = []` — **no Alpine source package is flagged as affected or fixed**. Its CPE-derived pseudo-packages are `c++`, `c_driver`, `node.js`, `php_driver`, `swift_driver` — all MongoDB products.\n- **Debian:** `security-tracker.debian.org/tracker/CVE-2021-32050` associates three source packages — `mongo-c-driver` (fixed 1.17.6-1+deb11u2 in bullseye), `php-mongodb`, `node-mongodb`. The `nodejs` source package is **not listed**. The Debian LTS announce referenced by NVD (`lists.debian.org/debian-lts-announce/2025/05/msg00027.html`) is for `mongo-c-driver`.\n- **Packages that actually carry the vulnerable code:** `mongo-c-driver` (+ mongo-cxx-driver), `php-mongodb` / PECL `mongodb` extension (relevant to alt-php, not here), the Swift driver, and the `mongodb` npm package. **None of these is shipped by any alt-nodejs package.**\n\n### 2. Upstream fix metadata (MongoDB Node.js driver)\n- Fix commit: `mongodb/node-mongodb-native@536e5ffbc941e8b99ad1c12c5239a688162a494e` — \"fix(NODE-3356): update redaction logic for command monitoring events (#2849)\", committed 2021-06-16.\n  https://github.com/mongodb/node-mongodb-native/commit/536e5ffbc941e8b99ad1c12c5239a688162a494e\n- Files changed: `src/cmap/command_monitoring_events.ts` (+10/-5), `test/functional/apm.test.js`.\n- Logic added: `HELLO_COMMANDS = {hello, ismaster, isMaster}` alongside `SENSITIVE_COMMANDS`; `maybeRedact()` now also redacts a hello/ismaster command when it carries `speculativeAuthenticate`.",
          "product_ids": [
            "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-dev-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-doc-14.21.3-r25.x86_64",
            "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.aarch64",
            "Alpine-Linux-3.24:alt-nodejs14-npm-14.21.3-r25.x86_64"
          ]
        },
        {
          "category": "impact",
          "date": "2026-07-29T07:48:09.420375Z",
          "details": "Not vulnerable\n\nalt-nodejs23 23.11.1: NOT AFFECTED — same basis: MongoDB driver component absent from the shipped tree; the CVE's CPE product `cpe:2.3:a:mongodb:node.js` is the MongoDB Node.js *driver*, not `cpe:2.3:a:nodejs:node.js`.\n\nPlatform in scope: alpinelinux3.24 (alt-nodejs23 23.11.1). No sibling precedent existed for this CVE at this version anywhere in ELSLANG; assessed from the shipped source and build configuration of alt-nodejs23, not from NVD version ranges.\n\nEvidence\n### 1. The CVE is scoped to MongoDB drivers, not to the Node.js runtime\n- NVD CPE configuration for CVE-2021-32050 (`services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2021-32050`) lists **only** vendor `mongodb` products:\n  - `cpe:2.3:a:mongodb:c_driver` >=1.0.0 <1.17.7\n  - `cpe:2.3:a:mongodb:c\\+\\+` >=1.0.0 <1.17.7\n  - `cpe:2.3:a:mongodb:node.js` >=3.6 <3.6.10, >=4.0 <4.17.0, >=5.0 <5.8.0\n  - `cpe:2.3:a:mongodb:php_driver` >=1.0.0 <1.9.2\n  - `cpe:2.3:a:mongodb:swift_driver` >=1.0.0 <1.1.1\n  There is **no** `cpe:2.3:a:nodejs:node.js` entry. CNA is `cna@mongodb.com`.\n- **Root cause of the tickets:** the CPE product string is literally `node.js` (under vendor `mongodb`). A matcher that keys on the product string and ignores the vendor field maps it onto the `nodejs` source package. The affected ranges (3.6.x / 4.x / 5.x) are `mongodb` npm-driver versions and do not correspond to Node.js release lines at all.\n- **Alpine (platform-matching vendor, alpinelinux3.23/3.24):** `https://security.alpinelinux.org/vuln/CVE-2021-32050` returns `state = []` — **no Alpine source package is flagged as affected or fixed**. Its CPE-derived pseudo-packages are `c++`, `c_driver`, `node.js`, `php_driver`, `swift_driver` — all MongoDB products.\n- **Debian:** `security-tracker.debian.org/tracker/CVE-2021-32050` associates three source packages — `mongo-c-driver` (fixed 1.17.6-1+deb11u2 in bullseye), `php-mongodb`, `node-mongodb`. The `nodejs` source package is **not listed**. The Debian LTS announce referenced by NVD (`lists.debian.org/debian-lts-announce/2025/05/msg00027.html`) is for `mongo-c-driver`.\n- **Packages that actually carry the vulnerable code:** `mongo-c-driver` (+ mongo-cxx-driver), `php-mongodb` / PECL `mongodb` extension (relevant to alt-php, not here), the Swift driver, and the `mongodb` npm package. **None of these is shipped by any alt-nodejs package.**\n\n### 2. Upstream fix metadata (MongoDB Node.js driver)\n- Fix commit: `mongodb/node-mongodb-native@536e5ffbc941e8b99ad1c12c5239a688162a494e` — \"fix(NODE-3356): update redaction logic for command monitoring events (#2849)\", committed 2021-06-16.\n  https://github.com/mongodb/node-mongodb-native/commit/536e5ffbc941e8b99ad1c12c5239a688162a494e\n- Files changed: `src/cmap/command_monitoring_events.ts` (+10/-5), `test/functional/apm.test.js`.\n- Logic added: `HELLO_COMMANDS = {hello, ismaster, isMaster}` alongside `SENSITIVE_COMMANDS`; `maybeRedact()` now also redacts a hello/ismaster command when it carries `speculativeAuthenticate`.",
          "product_ids": [
            "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-dev-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-doc-23.11.1-r15.x86_64",
            "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.aarch64",
            "Alpine-Linux-3.24:alt-nodejs23-npm-23.11.1-r15.x86_64"
          ]
        },
        {
          "category": "impact",
          "date": "2026-07-29T07:48:02.006237Z",
          "details": "Not vulnerable\n\nalt-nodejs16 16.20.2: NOT AFFECTED — same basis: the vulnerable code lives in the application-installed `mongodb` npm driver, not in the Node.js runtime; no MongoDB command-monitoring/wire-protocol code exists anywhere in the shipped tarball.\n\nPlatform in scope: alpinelinux3.24 (alt-nodejs16 16.20.2). No sibling precedent existed for this CVE at this version anywhere in ELSLANG; assessed from the shipped source and build configuration of alt-nodejs16, not from NVD version ranges.\n\nEvidence\n### 1. The CVE is scoped to MongoDB drivers, not to the Node.js runtime\n- NVD CPE configuration for CVE-2021-32050 (`services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2021-32050`) lists **only** vendor `mongodb` products:\n  - `cpe:2.3:a:mongodb:c_driver` >=1.0.0 <1.17.7\n  - `cpe:2.3:a:mongodb:c\\+\\+` >=1.0.0 <1.17.7\n  - `cpe:2.3:a:mongodb:node.js` >=3.6 <3.6.10, >=4.0 <4.17.0, >=5.0 <5.8.0\n  - `cpe:2.3:a:mongodb:php_driver` >=1.0.0 <1.9.2\n  - `cpe:2.3:a:mongodb:swift_driver` >=1.0.0 <1.1.1\n  There is **no** `cpe:2.3:a:nodejs:node.js` entry. CNA is `cna@mongodb.com`.\n- **Root cause of the tickets:** the CPE product string is literally `node.js` (under vendor `mongodb`). A matcher that keys on the product string and ignores the vendor field maps it onto the `nodejs` source package. The affected ranges (3.6.x / 4.x / 5.x) are `mongodb` npm-driver versions and do not correspond to Node.js release lines at all.\n- **Alpine (platform-matching vendor, alpinelinux3.23/3.24):** `https://security.alpinelinux.org/vuln/CVE-2021-32050` returns `state = []` — **no Alpine source package is flagged as affected or fixed**. Its CPE-derived pseudo-packages are `c++`, `c_driver`, `node.js`, `php_driver`, `swift_driver` — all MongoDB products.\n- **Debian:** `security-tracker.debian.org/tracker/CVE-2021-32050` associates three source packages — `mongo-c-driver` (fixed 1.17.6-1+deb11u2 in bullseye), `php-mongodb`, `node-mongodb`. The `nodejs` source package is **not listed**. The Debian LTS announce referenced by NVD (`lists.debian.org/debian-lts-announce/2025/05/msg00027.html`) is for `mongo-c-driver`.\n- **Packages that actually carry the vulnerable code:** `mongo-c-driver` (+ mongo-cxx-driver), `php-mongodb` / PECL `mongodb` extension (relevant to alt-php, not here), the Swift driver, and the `mongodb` npm package. **None of these is shipped by any alt-nodejs package.**\n\n### 2. Upstream fix metadata (MongoDB Node.js driver)\n- Fix commit: `mongodb/node-mongodb-native@536e5ffbc941e8b99ad1c12c5239a688162a494e` — \"fix(NODE-3356): update redaction logic for command monitoring events (#2849)\", committed 2021-06-16.\n  https://github.com/mongodb/node-mongodb-native/commit/536e5ffbc941e8b99ad1c12c5239a688162a494e\n- Files changed: `src/cmap/command_monitoring_events.ts` (+10/-5), `test/functional/apm.test.js`.\n- Logic added: `HELLO_COMMANDS = {hello, ismaster, isMaster}` alongside `SENSITIVE_COMMANDS`; `maybeRedact()` now also redacts a hello/ismaster command when it carries `speculativeAuthenticate`.",
          "product_ids": [
            "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-dev-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-doc-16.20.2-r20.x86_64",
            "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.aarch64",
            "Alpine-Linux-3.24:alt-nodejs16-npm-16.20.2-r20.x86_64"
          ]
        }
      ]
    }
  ]
}