[CLSA-2026:1778170333] Fix CVE(s): CVE-2026-21710
Type:
security
Severity:
Important
Release date:
2026-05-07 16:12:19 UTC
Description:
* SECURITY UPDATE: HTTP server crash on __proto__ header - debian/patches/CVE-2026-21710.patch: initialise headersDistinct and trailersDistinct destination maps with { __proto__: null } so a __proto__ request header no longer resolves to Object.prototype and cause an uncaught TypeError when req.headersDistinct or req.trailersDistinct is accessed - CVE-2026-21710
Updated packages:
  • alt-nodejs16-docs_16.20.2-17_amd64.deb
    sha:306ae7466fb83dad3b8e02a9e9fdc47d5ff53799
  • alt-nodejs16-nodejs_16.20.2-17_amd64.deb
    sha:20c3980ce6f022c10b1c87e5fe9775ebc6581e67
  • alt-nodejs16-nodejs-devel_16.20.2-17_amd64.deb
    sha:8844ee5662a812c6aa349dd692de527085e7584a
  • alt-nodejs16-npm_8.19.4-16.20.2-17_amd64.deb
    sha:9cb67e50e075747a2c7f30cbefabd7eed7f92db3
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.