VYPR

rpm package

almalinux/nodejs24-docs

pkg:rpm/almalinux/nodejs24-docs

Vulnerabilities (48)

  • CVE-2026-6734HigJun 17, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended desti

  • CVE-2026-6733LowJun 17, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request o

  • CVE-2026-11525LowJun 17, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens.

  • CVE-2026-12151HigJun 17, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and

  • CVE-2026-42338MedMay 12, 2026
    affected < 1:24.18.0-1.el10_2fixed 1:24.18.0-1.el10_2

    ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emi

  • CVE-2026-21717MedMar 30, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade perfo

  • CVE-2026-21716LowMar 30, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly patched. As a result, code running under `

  • CVE-2026-21715LowMar 30, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs

  • CVE-2026-21714MedMar 30, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned

  • CVE-2026-21713MedMar 30, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possibl

  • CVE-2026-21711MedMar 30, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can

  • CVE-2026-21710HigMar 30, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, c

  • CVE-2026-21712MedMar 30, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.

  • CVE-2026-27135HigMar 18, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the ap

  • CVE-2026-2581MedMar 12, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests could be accumulated in memory for downstream handler

  • CVE-2026-2229HigMar 12, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automatically advertises support for permessage-d

  • CVE-2026-1528HigMar 12, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version

  • CVE-2026-1527MedMar 12, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\r\n) to: * Inject arbitrary HTTP headers * Terminate the HTTP request prematurely and smuggle raw data to non-HTTP services (Redis, Mem

  • CVE-2026-1526HigMar 12, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without en

  • CVE-2026-1525MedMar 12, 2026
    affected < 1:24.14.1-2.el10_1fixed 1:24.14.1-2.el10_1

    Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the wire. Who is impacted: *