Release date:
2026-09-06 11:42:33 UTC
Description:
- CVE-2022-43548: harden the inspector IsIPAddress() to parse IPv4 and bracketed
IPv6 hosts with uv_inet_pton(), rejecting octal, hexadecimal and leading-zero
octet formats and treating 0.0.0.0/8 and ::/128 as non-routable, closing the
--inspect DNS-rebinding host allow-list bypass
- Folded in upstream follow-up 73fa9ab7a5, which keeps the IPv6 string
terminator inside the INET6_ADDRSTRLEN buffer
Updated packages:
-
alt-nodejs12-nodejs-12.22.12-31.el10.x86_64.rpm
sha:007d1dd8c7368decdc371aa05da46089dd4c0b246fa150fc8c6f38338feed235
-
alt-nodejs12-nodejs-devel-12.22.12-31.el10.x86_64.rpm
sha:7365d58babf69b2b3670ae3c8c4e6285b806f7268857bfbf442c9927c61ff948
-
alt-nodejs12-nodejs-docs-12.22.12-31.el10.noarch.rpm
sha:fc740df43e5db73c839373dac9f54bf4e41557ca1e83356f69532ae3c92bbf64
-
alt-nodejs12-npm-6.14.16-12.22.12.31.el10.x86_64.rpm
sha:4ca26724bc1a2b251c6f7ff38e0554891f7fbab8c7534131b2950160ce042d1b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.