[CLSA-2026:1787831977] alt-nodejs14-nodejs: Fix of CVE-2025-23167
Type:
security
Severity:
Moderate
Release date:
2026-08-27 11:59:46 UTC
Description:
- CVE-2025-23167: restore terminator validation in the loose state machine of the bundled llhttp 2.1.6 that Node compiles by default, so headers_almost_done, chunk_size_almost_done, the chunk_data_almost_done / chunk_data_almost_done_skip pair and res_line_almost_done require the LF (resp. CR then LF) after a CR instead of consuming any byte; a header block ending in "\r\n\rX" or a chunk terminated by "\rX" is now rejected with HPE_STRICT rather than swallowing the byte and parsing what follows as a second, smuggled request
CVEs fixed:
Updated packages:
  • alt-nodejs14-nodejs-14.21.3-28.el7.x86_64.rpm
    sha:f299481b1cea72cfbc3c9dad18fee3e9312e99e92be3cf5bff333c522503c35c
  • alt-nodejs14-nodejs-devel-14.21.3-28.el7.x86_64.rpm
    sha:9a7f2f0ff182a32a97a77055158dde06ab4f372e4cd8ea007323a325e654ed5e
  • alt-nodejs14-nodejs-docs-14.21.3-28.el7.noarch.rpm
    sha:d210af767e6d08f94729e5e1881ff2ad4aed4ffce4c3d6ccb2a440a367c1b921
  • alt-nodejs14-npm-6.14.18-14.21.3.28.el7.x86_64.rpm
    sha:8082680cb48ff7181f4b0e6b57b4b52b2d87d2069a8553880c7034476469f5b8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.