[CLSA-2026:1787830054] alt-nodejs14-nodejs: Fix of CVE-2025-23167
Type:
security
Severity:
Moderate
Release date:
2026-08-27 11:27:43 UTC
Description:
- CVE-2025-23167: restore terminator validation in the loose state machine of the bundled llhttp 2.1.6 that Node compiles by default, so headers_almost_done, chunk_size_almost_done, the chunk_data_almost_done / chunk_data_almost_done_skip pair and res_line_almost_done require the LF (resp. CR then LF) after a CR instead of consuming any byte; a header block ending in "\r\n\rX" or a chunk terminated by "\rX" is now rejected with HPE_STRICT rather than swallowing the byte and parsing what follows as a second, smuggled request
CVEs fixed:
Updated packages:
  • alt-nodejs14-nodejs-14.21.3-28.el9.x86_64.rpm
    sha:add2bc7f61f6fbca74eac1f76aec31f68b94ef874bc06fa5469a9830ad4b6391
  • alt-nodejs14-nodejs-devel-14.21.3-28.el9.x86_64.rpm
    sha:fd047d7373d0e8e2b1e1d6e9166d6731c476ded27c81584ac412a1515bc3f603
  • alt-nodejs14-nodejs-docs-14.21.3-28.el9.noarch.rpm
    sha:b21c6d578a4fa549a1e3289553d83a9c060c7879f225b5a022a444354e4262e2
  • alt-nodejs14-npm-6.14.18-14.21.3.28.el9.x86_64.rpm
    sha:822aa44294b4996e6109976b19919a0389aee492bb635c37605175401d8ac033
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.