[CLSA-2026:1777540500] alt-nodejs16-nodejs: Fix of CVE-2025-22150
Type:
security
Severity:
Moderate
Release date:
2026-05-04 12:01:50 UTC
Description:
- CVE-2025-22150: undici uses predictable Math.random() for multipart/form-data boundary, allowing attackers to tamper with backend requests under certain conditions
Updated packages:
  • alt-nodejs16-nodejs-16.20.2-17.el7.x86_64.rpm
    sha:68bd57ebe9ffccdd3a8f345fe87ad3a7f35db3d17bf46fd3d82bae1a3e6d49df
  • alt-nodejs16-nodejs-devel-16.20.2-17.el7.x86_64.rpm
    sha:cf46343c49235fddb35f64aa7a59728b7f71ae5076298c222901cca0a4baa426
  • alt-nodejs16-nodejs-docs-16.20.2-17.el7.noarch.rpm
    sha:764b6731da8c37811528930dbcbff3c4f8a7265ec37451a5d54dcd8ff9e1dd22
  • alt-nodejs16-npm-8.19.4-16.20.2.17.el7.x86_64.rpm
    sha:902463945b32c9363de4a86711c94cc05fed52551b5d058dc4472794954dd6ef
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.