VYPR

rpm package

almalinux/v8-13.6-devel

pkg:rpm/almalinux/v8-13.6-devel

Vulnerabilities (50)

  • CVE-2026-1526HigMar 12, 2026
    affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1

    The undici WebSocket client is vulnerable to a denial-of-service attack via unbounded memory consumption during permessage-deflate decompression. When a WebSocket connection negotiates the permessage-deflate extension, the client decompresses incoming compressed frames without en

  • CVE-2026-1525MedMar 12, 2026
    affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1

    Undici allows duplicate HTTP Content-Length headers when they are provided in an array with case-variant names (e.g., Content-Length and content-length). This produces malformed HTTP/1.1 requests with multiple conflicting Content-Length values on the wire. Who is impacted: *

  • CVE-2026-26996HigFeb 20, 2026
    affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1

    minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Versions 10.2.0 and below are vulnerable to Regular Expression Denial of Service (ReDoS) when a glob pattern contains many consecutive * wildcards followed by a literal charact

  • CVE-2026-25547CriFeb 4, 2026
    affected < 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1fixed 3:13.6.233.17-1.24.14.1.2.module_el9.7.0+222+ef1c61e1

    @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is vulnerable to a denial of service (DoS) issue caused by unbounded brace range expansion. When an attacker provides a pattern containing repeated nume

  • CVE-2026-21637HigJan 20, 2026
    affected < 3:13.6.233.17-1.24.13.0.0.module_el8.10.0+4113+bc863bc2fixed 3:13.6.233.17-1.24.13.0.0.module_el8.10.0+4113+bc863bc2

    A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), ca

  • CVE-2025-59466HigJan 20, 2026
    affected < 3:13.6.233.17-1.24.13.0.0.module_el8.10.0+4113+bc863bc2fixed 3:13.6.233.17-1.24.13.0.0.module_el8.10.0+4113+bc863bc2

    We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on('uncaughtException')`, the process terminates, making the crash unrecoverable. Applica

  • CVE-2025-59465HigJan 20, 2026
    affected < 3:13.6.233.17-1.24.13.0.0.module_el8.10.0+4113+bc863bc2fixed 3:13.6.233.17-1.24.13.0.0.module_el8.10.0+4113+bc863bc2

    A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects

  • CVE-2025-55132MedJan 20, 2026
    affected < 3:13.6.233.17-1.24.13.0.0.module_el8.10.0+4113+bc863bc2fixed 3:13.6.233.17-1.24.13.0.0.module_el8.10.0+4113+bc863bc2

    A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` even when the process has only read permissions. Unlike `utimes()`, `futimes()` does not apply the expected write-permission checks, which means file metadata can

  • CVE-2025-55131HigJan 20, 2026
    affected < 3:13.6.233.17-1.24.13.0.0.module_el8.10.0+4113+bc863bc2fixed 3:13.6.233.17-1.24.13.0.0.module_el8.10.0+4113+bc863bc2

    A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and other `TypedArray` instances like `Uint8Ar

  • CVE-2025-55130CriJan 20, 2026
    affected < 3:13.6.233.17-1.24.13.0.0.module_el8.10.0+4113+bc863bc2fixed 3:13.6.233.17-1.24.13.0.0.module_el8.10.0+4113+bc863bc2

    A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions using crafted relative symlink paths. By chaining directories and symlinks, a script granted access only to the current directory can escape the allowed path and

Page 3 of 3