Release date:
2026-05-01 10:45:29 UTC
Description:
* SECURITY UPDATE: undici predictable multipart/form-data boundary
- debian/patches/CVE-2025-22150.patch: replace Math.random() with
crypto.randomInt() for the boundary string in bundled undici
(deps/undici/src/lib/fetch/body.js). Math.random() output is
predictable from a few sampled values, allowing attackers who can
observe multipart requests to attacker-controlled servers to tamper
with subsequent requests to backend APIs.
- CVE-2025-22150
Updated packages:
-
alt-nodejs16-docs_16.20.2-16_amd64.deb
sha:fe29723d4eddb0ace2970f666e99a7c3ce19a3a2
-
alt-nodejs16-nodejs_16.20.2-16_amd64.deb
sha:aa7fe5a34d190abe1899cf0d758667e707082e27
-
alt-nodejs16-nodejs-devel_16.20.2-16_amd64.deb
sha:73329395fb14c5bff72b2152e10a582de42174b7
-
alt-nodejs16-npm_8.19.4-16.20.2-16_amd64.deb
sha:9f9cd420af9418a11b72071a54719c145281a808
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.