[CLSA-2025:1763397980] Fix CVE(s): CVE-2023-30589
Type:
security
Severity:
Important
Release date:
2025-11-17 16:46:24 UTC
Description:
* SECURITY UPDATE: HTTP Request Smuggling vulnerability via empty headers separated by CR - debian/patches/CVE-2023-30589.patch: fix llhttp parser to properly validate LF after CR in HTTP header fields, add lenient flag checks before allowing CR without LF, add test file to verify the fix prevents request smuggling attacks - CVE-2023-30589
Updated packages:
  • alt-nodejs14-docs_14.21.3-7_amd64.deb
    sha:5846a6a2fa1816f59636a7050f89776bca786c19
  • alt-nodejs14-nodejs_14.21.3-7_amd64.deb
    sha:8d93746718ef5a927bfce06c01f987c32a0b0c85
  • alt-nodejs14-nodejs-devel_14.21.3-7_amd64.deb
    sha:19762a998e87266f0aeee3e2d43e5db90e24da52
  • alt-nodejs14-npm_6.14.18-14.21.3.7_amd64.deb
    sha:970966f4fa913b5c04d76ad55618250adbdb4977
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.