[CLSA-2026:1772617597] nodejs: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-03-04 09:46:41 UTC
Description:
- CVE-2025-22150: fix issue where undici used Math.random() to choose boundary for multipart/form-data request, now uses secure random number generator - CVE-2023-39333: fix maliciously crafted export names injection of JavaScript code - Run full Node.js tests in %check - Fix comment typo in spec
Updated packages:
  • nodejs-16.20.2-8.el9_6.tuxcare.els9.x86_64.rpm
    sha:42d6152a12c27ab1fe57f789940d63bb90812d544bc36841a77592fa0b5fb33e
  • nodejs-devel-16.20.2-8.el9_6.tuxcare.els9.x86_64.rpm
    sha:b4d664d56e8c40d0bd6562a5a3f53d9990454150e4050cb9ec04ae01e8568583
  • nodejs-docs-16.20.2-8.el9_6.tuxcare.els9.noarch.rpm
    sha:86f9f0b3cc4646d40b73856c30267339ebdfb2fe6b4f269a0ab12da06b41bde2
  • nodejs-full-i18n-16.20.2-8.el9_6.tuxcare.els9.x86_64.rpm
    sha:e4cd922a0c419408f2877812f4e3634001e714f260595b0dcb50a584b6755905
  • nodejs-libs-16.20.2-8.el9_6.tuxcare.els9.i686.rpm
    sha:725c42e412ba09c5e5612ca288a127a62f70a812b5fc60eaf1a22ec487207bd0
  • nodejs-libs-16.20.2-8.el9_6.tuxcare.els9.x86_64.rpm
    sha:5848f225a75a7b868f737c85d45b04231ded00251333fc436769a2e7361860f4
  • npm-8.19.4_1.16.20.2-8.el9_6.tuxcare.els9.x86_64.rpm
    sha:a323b37ddb2eb2af6c05760d1ddcdedb1e8208017f4640196868112d8976c32f
  • v8-devel-9.4.146.26_1.16.20.2-8.el9_6.tuxcare.els9.x86_64.rpm
    sha:f23d2ffe72027cad9e001aba9986048c2b09e8deadf11e782a9fe5db6ebff7e6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.