Release date:
2026-08-27 11:27:43 UTC
Description:
- CVE-2025-23167: restore terminator validation in the loose state machine of the
bundled llhttp 2.1.6 that Node compiles by default, so headers_almost_done,
chunk_size_almost_done, the chunk_data_almost_done / chunk_data_almost_done_skip
pair and res_line_almost_done require the LF (resp. CR then LF) after a CR
instead of consuming any byte; a header block ending in "\r\n\rX" or a chunk
terminated by "\rX" is now rejected with HPE_STRICT rather than swallowing the
byte and parsing what follows as a second, smuggled request
Updated packages:
-
alt-nodejs14-nodejs-14.21.3-28.el9.x86_64.rpm
sha:add2bc7f61f6fbca74eac1f76aec31f68b94ef874bc06fa5469a9830ad4b6391
-
alt-nodejs14-nodejs-devel-14.21.3-28.el9.x86_64.rpm
sha:fd047d7373d0e8e2b1e1d6e9166d6731c476ded27c81584ac412a1515bc3f603
-
alt-nodejs14-nodejs-docs-14.21.3-28.el9.noarch.rpm
sha:b21c6d578a4fa549a1e3289553d83a9c060c7879f225b5a022a444354e4262e2
-
alt-nodejs14-npm-6.14.18-14.21.3.28.el9.x86_64.rpm
sha:822aa44294b4996e6109976b19919a0389aee492bb635c37605175401d8ac033
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.