rpm package
almalinux/v8-13.6-devel
pkg:rpm/almalinux/v8-13.6-devel
Vulnerabilities (50)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-6734 | Hig | 7.5 | < 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e | 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e | Jun 17, 2026 | Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended desti | |
| CVE-2026-6733 | Low | 3.7 | < 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e | 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e | Jun 17, 2026 | Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request o | |
| CVE-2026-11525 | Low | 3.7 | < 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e | 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e | Jun 17, 2026 | Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. | |
| CVE-2026-12151 | Hig | 7.5 | < 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e | 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e | Jun 17, 2026 | Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and | |
| CVE-2026-11824 | Hig | 7.8 | < 3:13.6.233.17-1.24.18.0.3.module_el8.10.0+4250+09238ed4 | 3:13.6.233.17-1.24.18.0.3.module_el8.10.0+4250+09238ed4 | Jun 9, 2026 | SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value sma | |
| CVE-2026-11822 | Hig | 7.8 | < 3:13.6.233.17-1.24.18.0.3.module_el8.10.0+4250+09238ed4 | 3:13.6.233.17-1.24.18.0.3.module_el8.10.0+4250+09238ed4 | Jun 9, 2026 | SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigge | |
| CVE-2026-42338 | Med | 6.1 | < 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e | 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e | May 12, 2026 | ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emi | |
| CVE-2026-21717 | Med | 5.9 | < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | Mar 30, 2026 | A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade perfo | |
| CVE-2026-21716 | Low | 3.3 | < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | Mar 30, 2026 | An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly patched. As a result, code running under ` | |
| CVE-2026-21715 | Low | 3.3 | < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | Mar 30, 2026 | A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs | |
| CVE-2026-21714 | Med | 5.3 | < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | Mar 30, 2026 | A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned | |
| CVE-2026-21713 | Med | 5.9 | < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | Mar 30, 2026 | A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possibl | |
| CVE-2026-21711 | Med | 5.3 | < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | Mar 30, 2026 | A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can | |
| CVE-2026-21710 | Hig | 7.5 | < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | Mar 30, 2026 | A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, c | |
| CVE-2026-21712 | Med | 6.5 | < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | Mar 30, 2026 | A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process. | |
| CVE-2026-27135 | Hig | 7.5 | < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | Mar 18, 2026 | nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the ap | |
| CVE-2026-2581 | Med | 5.9 | < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | Mar 12, 2026 | This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests could be accumulated in memory for downstream handler | |
| CVE-2026-2229 | Hig | 7.5 | < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | Mar 12, 2026 | ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automatically advertises support for permessage-d | |
| CVE-2026-1528 | Hig | 7.5 | < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | Mar 12, 2026 | ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version | |
| CVE-2026-1527 | Med | 4.6 | < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1 | Mar 12, 2026 | ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\r\n) to: * Inject arbitrary HTTP headers * Terminate the HTTP request prematurely and smuggle raw data to non-HTTP services (Redis, Mem |
- affected < 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613efixed 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e
Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended desti
- affected < 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613efixed 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e
Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request o
- affected < 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613efixed 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e
Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens.
- affected < 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613efixed 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e
Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and
- affected < 3:13.6.233.17-1.24.18.0.3.module_el8.10.0+4250+09238ed4fixed 3:13.6.233.17-1.24.18.0.3.module_el8.10.0+4250+09238ed4
SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value sma
- affected < 3:13.6.233.17-1.24.18.0.3.module_el8.10.0+4250+09238ed4fixed 3:13.6.233.17-1.24.18.0.3.module_el8.10.0+4250+09238ed4
SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigge
- affected < 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613efixed 3:13.6.233.17-1.24.18.0.1.module_el9.8.0+277+61fc613e
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before embedding it in the HTML strings they return, and AddressError.parseMessage (emi
- affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1
A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade perfo
- affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1
An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without the required permission checks, while their callback-based equivalents (`fs.fchmod()`, `fs.fchown()`) were correctly patched. As a result, code running under `
- affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks, while all comparable filesystem functions correctly enforce them. As a result, code running under `--permission` with restricted `--allow-fs
- affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1
A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned
- affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1
A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking timing information proportional to the number of matching bytes. Under certain threat models where high-resolution timing measurements are possibl
- affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1
A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission checks, while all comparable network paths correctly enforce them. As a result, code running under `--permission` without `--allow-net` can
- affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1
A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the application accesses `req.headersDistinct`. When this occurs, `dest["__proto__"]` resolves to `Object.prototype` rather than `undefined`, c
- affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1
A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationalized domain name (IDN) containing invalid characters, crashing the Node.js process.
- affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1
nghttp2 is an implementation of the Hypertext Transfer Protocol version 2 in C. Prior to version 1.68.1, the nghttp2 library stops reading the incoming data when user facing public API `nghttp2_session_terminate_session` or `nghttp2_session_terminate_session2` is called by the ap
- affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1
This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS). In vulnerable Undici versions, when interceptors.deduplicate() is enabled, response data for deduplicated requests could be accumulated in memory for downstream handler
- affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1
ImpactThe undici WebSocket client is vulnerable to a denial-of-service attack due to improper validation of the server_max_window_bits parameter in the permessage-deflate extension. When a WebSocket client connects to a server, it automatically advertises support for permessage-d
- affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1
ImpactA server can reply with a WebSocket frame using the 64-bit length form and an extremely large length. undici's ByteParser overflows internal math, ends up in an invalid state, and throws a fatal TypeError that terminates the process. Patches Patched in the undici version
- affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1
ImpactWhen an application passes user-controlled input to the upgrade option of client.request(), an attacker can inject CRLF sequences (\r\n) to: * Inject arbitrary HTTP headers * Terminate the HTTP request prematurely and smuggle raw data to non-HTTP services (Redis, Mem
Page 2 of 3