Release date:
2026-07-31 16:15:15 UTC
Description:
- CVE-2025-23167: restore terminator validation in the loose state machine of the
bundled llhttp 6.1.1 that Node compiles by default, so headers_almost_done,
chunk_size_almost_done, chunk_data_almost_done and res_line_almost_done require
the LF after a CR instead of consuming any byte; a header block ending in
"\r\n\rX" or a chunk terminated by "\rX" is now rejected with HPE_STRICT rather
than swallowing the byte and parsing what follows as a second, smuggled request
Updated packages:
-
alt-nodejs18-nodejs-18.20.8-17.el10.x86_64.rpm
sha:1b4530c2dab515aa333da535e548c592c267bb6f6434f6da6b25b61476a3e285
-
alt-nodejs18-nodejs-devel-18.20.8-17.el10.x86_64.rpm
sha:a10cbf5df927ea5641eb2c0ae81ae848b794f9d93385ca897cb5a2a5a7ca8bac
-
alt-nodejs18-nodejs-docs-18.20.8-17.el10.noarch.rpm
sha:a094d37c34d8d9c65bdafa66e8c0675dd0dfbaf3833811ef26e6dc10815029eb
-
alt-nodejs18-npm-10.8.2-18.20.8.17.el10.x86_64.rpm
sha:4f8a163ed4e094ee793539885d19b21d2b305f88ae1dad8f1f7cfca5ac597ff3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.