Release date:
2026-09-06 13:40:47 UTC
Description:
* SECURITY UPDATE: --inspect DNS rebinding via permissive IP validation
- debian/patches/CVE-2022-43548.patch: rewrite the inspector's
IsIPAddress() to parse IPv4 (dotted-decimal only) and bracketed IPv6
hosts with uv_inet_pton(), rejecting octal, hexadecimal and leading-zero
octet formats and treating 0.0.0.0/8 and ::/128 as non-routable, so a
Host header IP that a browser resolves differently can no longer bypass
the inspector host allow-list (backport of nodejs/node 2b433af094,
with follow-up 73fa9ab7a5 folded in so the IPv6 string terminator
is written inside the INET6_ADDRSTRLEN buffer)
- CVE-2022-43548
Updated packages:
-
alt-nodejs12-docs_12.22.12-28_amd64.deb
sha:e498433e47207b965a96de4e12e2fce0bd586709
-
alt-nodejs12-nodejs_12.22.12-28_amd64.deb
sha:7452592c2c82557134136c27fd4bd3775399608f
-
alt-nodejs12-nodejs-devel_12.22.12-28_amd64.deb
sha:c05a53e67f88ce799624fa79dca5722c476a21b5
-
alt-nodejs12-npm_6.14.16-12.22.12.28_amd64.deb
sha:05bc89acb3151afb58d90a262c0aba108bb606b1
-
alt-nodejs12-docs_12.22.12-28_arm64.deb
sha:00d6130f14923812b87cf7db23a9a9e0b94bfbfc
-
alt-nodejs12-nodejs_12.22.12-28_arm64.deb
sha:271609715817cae6346155dc0f067e4bb6ed0735
-
alt-nodejs12-nodejs-devel_12.22.12-28_arm64.deb
sha:5ac467a702657d192198882c84ebb906bb5288a9
-
alt-nodejs12-npm_6.14.16-12.22.12.28_arm64.deb
sha:913c3bb0773c147f24917a7bb0b420acfdab5269
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.