[CLSA-2026:1779443751] alt-nodejs18-nodejs: Fix of CVE-2026-21713
Type:
security
Severity:
Moderate
Release date:
2026-05-22 09:55:56 UTC
Description:
- CVE-2026-21713: use CRYPTO_memcmp instead of memcmp in Web Cryptography HMAC signature verification to prevent timing attacks
Updated packages:
  • alt-nodejs18-nodejs-18.20.8-10.el9.x86_64.rpm
    sha:4e2b5f7642d49fbe553ba0af3a488d09b7d90bb135a05047b508493e42a823b4
  • alt-nodejs18-nodejs-devel-18.20.8-10.el9.x86_64.rpm
    sha:c556b97e869454fe4c6c38ef99675b2a191adf9b6abe4c019e7d6f9064aee265
  • alt-nodejs18-nodejs-docs-18.20.8-10.el9.noarch.rpm
    sha:e4b7abc7dfe32600c629eaa0add1c629df5b87756af93b5a65560d51e11f64d2
  • alt-nodejs18-npm-10.8.2-18.20.8.10.el9.x86_64.rpm
    sha:010db4f90db5bc8936f1ecb9d6fa62ff706fd6cbf2d8b5d8c3c48cf9ec95d21a
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.