[CLSA-2026:1778170084] Fix CVE(s): CVE-2026-21710
Type:
security
Severity:
Important
Release date:
2026-05-07 16:08:17 UTC
Description:
* SECURITY UPDATE: HTTP server crash on __proto__ header - debian/patches/CVE-2026-21710.patch: initialise headersDistinct and trailersDistinct destination maps with { __proto__: null } so a __proto__ request header no longer resolves to Object.prototype and cause an uncaught TypeError when req.headersDistinct or req.trailersDistinct is accessed - CVE-2026-21710
Updated packages:
  • alt-nodejs16-docs_16.20.2-17_amd64.deb
    sha:32a3af98dc470e4c9833a9add7b286c784c42139
  • alt-nodejs16-nodejs_16.20.2-17_amd64.deb
    sha:ac2cf107a6cbad416bbebb04d2191da43dc07ae0
  • alt-nodejs16-nodejs-devel_16.20.2-17_amd64.deb
    sha:8db5f2161251866bff78a19a40ddbe965162e3c0
  • alt-nodejs16-npm_8.19.4-16.20.2-17_amd64.deb
    sha:34eeb898d7c51873102424a46de842252c6c3737
  • alt-nodejs16-docs_16.20.2-17_arm64.deb
    sha:7dd5c1fb1a19cbf19db61e3397af32a82ae55241
  • alt-nodejs16-nodejs_16.20.2-17_arm64.deb
    sha:0b14c195d597cbade82a88c8b0ef3a8338f56074
  • alt-nodejs16-nodejs-devel_16.20.2-17_arm64.deb
    sha:61cd5c465211d26444c9dfac60d6ced0e28f67a9
  • alt-nodejs16-npm_8.19.4-16.20.2-17_arm64.deb
    sha:79126c0518472c88c6b2c421e461735d0166bb34
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.