Release date:
2026-08-27 11:59:46 UTC
Description:
- CVE-2025-23167: restore terminator validation in the loose state machine of the
bundled llhttp 2.1.6 that Node compiles by default, so headers_almost_done,
chunk_size_almost_done, the chunk_data_almost_done / chunk_data_almost_done_skip
pair and res_line_almost_done require the LF (resp. CR then LF) after a CR
instead of consuming any byte; a header block ending in "\r\n\rX" or a chunk
terminated by "\rX" is now rejected with HPE_STRICT rather than swallowing the
byte and parsing what follows as a second, smuggled request
Updated packages:
-
alt-nodejs14-nodejs-14.21.3-28.el7.x86_64.rpm
sha:f299481b1cea72cfbc3c9dad18fee3e9312e99e92be3cf5bff333c522503c35c
-
alt-nodejs14-nodejs-devel-14.21.3-28.el7.x86_64.rpm
sha:9a7f2f0ff182a32a97a77055158dde06ab4f372e4cd8ea007323a325e654ed5e
-
alt-nodejs14-nodejs-docs-14.21.3-28.el7.noarch.rpm
sha:d210af767e6d08f94729e5e1881ff2ad4aed4ffce4c3d6ccb2a440a367c1b921
-
alt-nodejs14-npm-6.14.18-14.21.3.28.el7.x86_64.rpm
sha:8082680cb48ff7181f4b0e6b57b4b52b2d87d2069a8553880c7034476469f5b8
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.