{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "Extend the ALTNJS-278 bundled-zlib build to el6. The guard added in\n  12.22.12-27 only excluded el7, so CL6 kept getting --shared-zlib and linked\n  the base OS zlib 1.2.3, which is older than the 1.2.7 that made npm fail on\n  CL7. npm install against registry.npmjs.org fails there with\n  \"Z_STREAM_ERROR: Invalid response body ...: Zlib error\". Building against\n  node's bundled deps/zlib (>= 1.2.11) fixes it, as it did on el7. No other\n  platform changes: el8+ still links the system zlib.\n- Build el6 against alt-python27. el6's base python is 2.6.6 and Node.js 12\n  requires 2.7, so ./configure aborted with \"Please use Python 2.7\". el6 now\n  BuildRequires alt-python27 (2.7.18, from the alt-python flavour repo) and\n  puts it on PATH, as alt-nodejs14 already does. This also fixes the shebang\n  rewrites in %prep, which emitted a literal \"%{__python2}\" on el6 because\n  el6's rpm does not define that macro.\n- Fix the i686 build of the now-bundled deps/zlib. zlib.gyp compiles the SSE2\n  paths without adding -msse2, which only works where SSE2 is in the baseline\n  ABI; on i686 gcc rejects the always_inline intrinsics with \"target specific\n  option mismatch\". Backport the one-line-per-file sse2 target pragma that\n  node 14's bundled zlib already carries (chunkcopy.h, fill_window_sse.c);\n  a no-op on x86_64.",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
        "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_alt_nodejs/el6/advisories/2026/clsa-2026_1788389923.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-02T23:01:42Z",
      "generator": {
        "date": "2026-09-02T23:01:42Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1788389923",
      "initial_release_date": "2026-09-02T23:01:42Z",
      "revision_history": [
        {
          "date": "2026-09-02T23:01:42Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "alt-nodejs12-nodejs: Fix of 26 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 6",
                "product": {
                  "name": "Community Enterprise Operating System 6",
                  "product_id": "CentOS-6",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:6:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          }
        ],
        "category": "vendor",
        "name": "Cloud Linux Software, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64",
                "product": {
                  "name": "alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64",
                  "product_id": "alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-nodejs12-npm@6.14.16-12.22.12.29.el6?arch=x86_64&epoch=1&os_name=centos&os_version=6"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
                "product": {
                  "name": "alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
                  "product_id": "alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-nodejs12-nodejs-devel@12.22.12-29.el6?arch=x86_64&os_name=centos&os_version=6"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
                "product": {
                  "name": "alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
                  "product_id": "alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-nodejs12-nodejs@12.22.12-29.el6?arch=x86_64&os_name=centos&os_version=6"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
                "product": {
                  "name": "alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
                  "product_id": "alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-nodejs12-nodejs-docs@12.22.12-29.el6?arch=noarch&os_name=centos&os_version=6"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        },
        "product_reference": "alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64"
        },
        "product_reference": "alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64 as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64"
        },
        "product_reference": "alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
        "relates_to_product_reference": "CentOS-6"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch as a component of Community Enterprise Operating System 6",
          "product_id": "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch"
        },
        "product_reference": "alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
        "relates_to_product_reference": "CentOS-6"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2024-22025",
      "cwe": {
        "id": "CWE-404",
        "name": "Improper Resource Shutdown or Release"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability in Node.js has been identified, allowing for a Denial of Service (DoS) attack through resource exhaustion when using the fetch() function to retrieve content from an untrusted URL.\nThe vulnerability stems from the fact that the fetch() function in Node.js always decodes Brotli, making it possible for an attacker to cause resource exhaustion when fetching content from an untrusted URL.\nAn attacker controlling the URL passed into fetch() can exploit this vulnerability to exhaust memory, potentially leading to process termination, depending on the system configuration.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2024-22025"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2284065",
          "url": "https://hackerone.com/reports/2284065"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/03/msg00029.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00029.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20240517-0008/",
          "url": "https://security.netapp.com/advisory/ntap-20240517-0008/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html"
        }
      ],
      "release_date": "2024-03-19T05:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2023-30589",
      "notes": [
        {
          "category": "description",
          "text": "The llhttp parser in the http module in Node v20.2.0 does not strictly use the CRLF sequence to delimit HTTP requests. This can lead to HTTP Request Smuggling (HRS).\r\n\r\nThe CR character (without LF) is sufficient to delimit HTTP header fields in the llhttp parser. According to RFC7230 section 3, only the CRLF sequence should delimit each header-field. This impacts all Node.js active versions: v16, v18, and, v20",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2023-30589"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2001873",
          "url": "https://hackerone.com/reports/2001873"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HMEELCREWMRT6NS7HWXLA6XFLLMO36HE/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HMEELCREWMRT6NS7HWXLA6XFLLMO36HE/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IV326O2X4BE3SINX5FJHMAKVHUAA4ZYF/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/IV326O2X4BE3SINX5FJHMAKVHUAA4ZYF/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UEJWL67XR67JAGEL2ZK22NA3BRKNMZNY/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UEJWL67XR67JAGEL2ZK22NA3BRKNMZNY/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCVG4TQRGTK4LKAZKVEQAUEJM7DUACYE/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VCVG4TQRGTK4LKAZKVEQAUEJM7DUACYE/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VEEQIN5242K5NBE2CZ4DYTNA5B4YTYE5/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VEEQIN5242K5NBE2CZ4DYTNA5B4YTYE5/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VKFMKD4MJZIKFQJAAJ4VZ2FHIJ764A76/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VKFMKD4MJZIKFQJAAJ4VZ2FHIJ764A76/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20230803-0009/",
          "url": "https://security.netapp.com/advisory/ntap-20230803-0009/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20240621-0006/",
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html"
        }
      ],
      "release_date": "2023-07-01T00:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2022-32213",
      "cwe": {
        "id": "CWE-444",
        "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')"
      },
      "notes": [
        {
          "category": "description",
          "text": "The llhttp parser <v14.20.1, <v16.17.1 and <v18.9.1 in the http module in Node.js does not correctly parse and validate Transfer-Encoding headers and can lead to HTTP Request Smuggling (HRS).",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2022-32213"
        },
        {
          "category": "external",
          "summary": "https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf",
          "url": "https://cert-portal.siemens.com/productcert/pdf/ssa-332410.pdf"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/1524555",
          "url": "https://hackerone.com/reports/1524555"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ICG6CSIB3GUWH5DUSQEVX53MOJW7LYK/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2ICG6CSIB3GUWH5DUSQEVX53MOJW7LYK/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QCNN3YG2BCLS4ZEKJ3CLSUT6AS7AXTH3/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/QCNN3YG2BCLS4ZEKJ3CLSUT6AS7AXTH3/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMQK5L5SBYD47QQZ67LEMHNQ662GH3OY/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VMQK5L5SBYD47QQZ67LEMHNQ662GH3OY/"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/july-2022-security-releases/",
          "url": "https://nodejs.org/en/blog/vulnerability/july-2022-security-releases/"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2023/dsa-5326",
          "url": "https://www.debian.org/security/2023/dsa-5326"
        }
      ],
      "release_date": "2022-07-14T15:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2023-38552",
      "cwe": {
        "id": "CWE-345",
        "name": "Insufficient Verification of Data Authenticity"
      },
      "notes": [
        {
          "category": "description",
          "text": "When the Node.js policy feature checks the integrity of a resource against a trusted manifest, the application can intercept the operation and return a forged checksum to the node's policy implementation, thus effectively disabling the integrity check.\nImpacts:\nThis vulnerability affects all users using the experimental policy mechanism in all active release lines: 18.x and, 20.x.\nPlease note that at the time this CVE was issued, the policy mechanism is an experimental feature of Node.js.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2023-38552"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2094235",
          "url": "https://hackerone.com/reports/2094235"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20231116-0013/",
          "url": "https://security.netapp.com/advisory/ntap-20231116-0013/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20241108-0002/",
          "url": "https://security.netapp.com/advisory/ntap-20241108-0002/"
        }
      ],
      "release_date": "2023-10-18T04:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2023-32002",
      "notes": [
        {
          "category": "description",
          "text": "The use of `Module._load()` can bypass the policy mechanism and require modules outside of the policy.json definition for a given module.\n\nThis vulnerability affects all users using the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x.\n\nPlease note that at the time this CVE was issued, the policy is an experimental feature of Node.js.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2023-32002"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/1960870",
          "url": "https://hackerone.com/reports/1960870"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20230915-0009/",
          "url": "https://security.netapp.com/advisory/ntap-20230915-0009/"
        }
      ],
      "release_date": "2023-08-21T17:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2025-59465",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unhandled `TLSSocket` error `ECONNRESET`. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects applications that do not attach explicit error handlers to secure sockets, for example:\n```\nserver.on('secureConnection', socket => {\n  socket.on('error', err => {\n    console.log(err)\n  })\n})\n```",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2025-59465"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/december-2025-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/december-2025-security-releases"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:1842",
          "url": "https://access.redhat.com/errata/RHSA-2026:1842"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:1843",
          "url": "https://access.redhat.com/errata/RHSA-2026:1843"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2420",
          "url": "https://access.redhat.com/errata/RHSA-2026:2420"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2421",
          "url": "https://access.redhat.com/errata/RHSA-2026:2421"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2422",
          "url": "https://access.redhat.com/errata/RHSA-2026:2422"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2767",
          "url": "https://access.redhat.com/errata/RHSA-2026:2767"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2768",
          "url": "https://access.redhat.com/errata/RHSA-2026:2768"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2781",
          "url": "https://access.redhat.com/errata/RHSA-2026:2781"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2782",
          "url": "https://access.redhat.com/errata/RHSA-2026:2782"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2783",
          "url": "https://access.redhat.com/errata/RHSA-2026:2783"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2864",
          "url": "https://access.redhat.com/errata/RHSA-2026:2864"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2899",
          "url": "https://access.redhat.com/errata/RHSA-2026:2899"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:6402",
          "url": "https://access.redhat.com/errata/RHSA-2026:6402"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:6431",
          "url": "https://access.redhat.com/errata/RHSA-2026:6431"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:7386",
          "url": "https://access.redhat.com/errata/RHSA-2026:7386"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:7387",
          "url": "https://access.redhat.com/errata/RHSA-2026:7387"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2025-59465",
          "url": "https://access.redhat.com/security/cve/CVE-2025-59465"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2431349",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431349"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59465.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59465.json"
        }
      ],
      "release_date": "2026-01-20T21:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-48934",
      "notes": [
        {
          "category": "description",
          "text": "A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-48934"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases"
        }
      ],
      "release_date": "2026-06-26T02:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2023-30590",
      "notes": [
        {
          "category": "description",
          "text": "The generateKeys() API function returned from crypto.createDiffieHellman() only generates missing (or outdated) keys, that is, it only generates a private key if none has been set yet, but the function is also needed to compute the corresponding public key after calling setPrivateKey(). However, the documentation says this API call: \"Generates private and public Diffie-Hellman key values\".\n\nThe documented behavior is very different from the actual behavior, and this difference could easily lead to security issues in applications that use these APIs as the DiffieHellman may be used as the basis for application-level security, implications are consequently broad.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2023-30590"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/03/msg00029.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00029.html"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/june-2023-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/june-2023-security-releases"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20241101-0011/",
          "url": "https://security.netapp.com/advisory/ntap-20241101-0011/"
        }
      ],
      "release_date": "2023-11-28T20:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-22019",
      "cwe": {
        "id": "CWE-404",
        "name": "Improper Resource Shutdown or Release"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability in Node.js HTTP servers allows an attacker to send a specially crafted HTTP request with chunked encoding, leading to resource exhaustion and denial of service (DoS). The server reads an unbounded number of bytes from a single connection, exploiting the lack of limitations on chunk extension bytes. The issue can cause CPU and network bandwidth exhaustion, bypassing standard safeguards like timeouts and body size limits.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2024-22019"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2024/03/11/1",
          "url": "http://www.openwall.com/lists/oss-security/2024/03/11/1"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2233486",
          "url": "https://hackerone.com/reports/2233486"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20240315-0004/",
          "url": "https://security.netapp.com/advisory/ntap-20240315-0004/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html"
        }
      ],
      "release_date": "2024-02-20T02:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-21717",
      "cwe": {
        "id": "CWE-328",
        "name": "Use of Weak Hash"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash collisions trivially predictable. By crafting a request that causes many such collisions in V8's internal string table, an attacker can significantly degrade performance of the Node.js process.\r\n\r\nThe most common trigger is any endpoint that calls `JSON.parse()` on attacker-controlled input, as JSON parsing automatically internalizes short strings into the affected hash table.\r\n\r\nThis vulnerability affects **20.x, 22.x, 24.x, and 25.x**.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-21717"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/march-2026-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/march-2026-security-releases"
        }
      ],
      "release_date": "2026-03-30T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2023-32559",
      "notes": [
        {
          "category": "description",
          "text": "A privilege escalation vulnerability exists in the experimental policy mechanism in all active release lines: 16.x, 18.x and, 20.x. The use of the deprecated API `process.binding()` can bypass the policy mechanism by requiring internal modules and eventually take advantage of `process.binding('spawn_sync')` run arbitrary code, outside of the limits defined in a `policy.json` file. Please note that at the time this CVE was issued, the policy is an experimental feature of Node.js.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2023-32559"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/1946470",
          "url": "https://hackerone.com/reports/1946470"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20231006-0006/",
          "url": "https://security.netapp.com/advisory/ntap-20231006-0006/"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html"
        }
      ],
      "release_date": "2023-08-24T02:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2023-23918",
      "cwe": {
        "id": "CWE-863",
        "name": "Incorrect Authorization"
      },
      "notes": [
        {
          "category": "description",
          "text": "A privilege escalation vulnerability exists in Node.js <19.6.1, <18.14.1, <16.19.1 and <14.21.3 that made it possible to bypass the experimental Permissions (https://nodejs.org/api/permissions.html) feature in Node.js and access non authorized modules by using process.mainModule.require(). This only affects users who had enabled the experimental permissions option with --experimental-policy.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2023-23918"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/february-2023-security-releases/",
          "url": "https://nodejs.org/en/blog/vulnerability/february-2023-security-releases/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20230316-0008/",
          "url": "https://security.netapp.com/advisory/ntap-20230316-0008/"
        }
      ],
      "release_date": "2023-02-23T20:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-48933",
      "cwe": {
        "id": "CWE-190",
        "name": "Integer Overflow or Wraparound"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-48933"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:28727",
          "url": "https://access.redhat.com/errata/RHSA-2026:28727"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:29012",
          "url": "https://access.redhat.com/errata/RHSA-2026:29012"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:30172",
          "url": "https://access.redhat.com/errata/RHSA-2026:30172"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:35841",
          "url": "https://access.redhat.com/errata/RHSA-2026:35841"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:35842",
          "url": "https://access.redhat.com/errata/RHSA-2026:35842"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:35891",
          "url": "https://access.redhat.com/errata/RHSA-2026:35891"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:35892",
          "url": "https://access.redhat.com/errata/RHSA-2026:35892"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:39246",
          "url": "https://access.redhat.com/errata/RHSA-2026:39246"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:39868",
          "url": "https://access.redhat.com/errata/RHSA-2026:39868"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:41947",
          "url": "https://access.redhat.com/errata/RHSA-2026:41947"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:52399",
          "url": "https://access.redhat.com/errata/RHSA-2026:52399"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:7378",
          "url": "https://access.redhat.com/errata/RHSA-2026:7378"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:9455",
          "url": "https://access.redhat.com/errata/RHSA-2026:9455"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-48933",
          "url": "https://access.redhat.com/security/cve/CVE-2026-48933"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2493331",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493331"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48933.json"
        }
      ],
      "release_date": "2026-06-26T02:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-48937",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-48937"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/3658225",
          "url": "https://hackerone.com/reports/3658225"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases"
        }
      ],
      "release_date": "2026-06-18T19:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2023-46809",
      "cwe": {
        "id": "CWE-385",
        "name": "Covert Timing Channel"
      },
      "notes": [
        {
          "category": "description",
          "text": "Node.js versions which bundle an unpatched version of OpenSSL or run against a dynamically linked version of OpenSSL which are unpatched are vulnerable to the Marvin Attack - https://people.redhat.com/~hkario/marvin/, if PCKS #1 v1.5 padding is allowed when performing RSA descryption using a private key.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2023-46809"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/february-2024-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/february-2024-security-releases"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/03/msg00029.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/03/msg00029.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html"
        }
      ],
      "release_date": "2024-09-07T16:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-55131",
      "cwe": {
        "id": "CWE-120",
        "name": "Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and other `TypedArray` instances like `Uint8Array` may contain leftover data from previous operations, allowing in-process secrets like tokens or passwords to leak or causing data corruption. While exploitation typically requires precise timing or in-process code execution, it can become remotely exploitable when untrusted input influences workload and timeouts, leading to potential confidentiality and integrity impact.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2025-55131"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/december-2025-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/december-2025-security-releases"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:1842",
          "url": "https://access.redhat.com/errata/RHSA-2026:1842"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:1843",
          "url": "https://access.redhat.com/errata/RHSA-2026:1843"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2420",
          "url": "https://access.redhat.com/errata/RHSA-2026:2420"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2421",
          "url": "https://access.redhat.com/errata/RHSA-2026:2421"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2422",
          "url": "https://access.redhat.com/errata/RHSA-2026:2422"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2767",
          "url": "https://access.redhat.com/errata/RHSA-2026:2767"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2768",
          "url": "https://access.redhat.com/errata/RHSA-2026:2768"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2781",
          "url": "https://access.redhat.com/errata/RHSA-2026:2781"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2782",
          "url": "https://access.redhat.com/errata/RHSA-2026:2782"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2783",
          "url": "https://access.redhat.com/errata/RHSA-2026:2783"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2864",
          "url": "https://access.redhat.com/errata/RHSA-2026:2864"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:2899",
          "url": "https://access.redhat.com/errata/RHSA-2026:2899"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:6402",
          "url": "https://access.redhat.com/errata/RHSA-2026:6402"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:6431",
          "url": "https://access.redhat.com/errata/RHSA-2026:6431"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:7386",
          "url": "https://access.redhat.com/errata/RHSA-2026:7386"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:7387",
          "url": "https://access.redhat.com/errata/RHSA-2026:7387"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2025-55131",
          "url": "https://access.redhat.com/security/cve/CVE-2025-55131"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2431350",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2431350"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55131.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-55131.json"
        }
      ],
      "release_date": "2026-01-20T21:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-48928",
      "cwe": {
        "id": "CWE-284",
        "name": "Improper Access Control"
      },
      "notes": [
        {
          "category": "description",
          "text": "A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-48928"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases"
        }
      ],
      "release_date": "2026-06-26T02:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-48930",
      "cwe": {
        "id": "CWE-284",
        "name": "Improper Access Control"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-48930"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases"
        }
      ],
      "release_date": "2026-06-26T02:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2026-21637",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCallback` are in use. Synchronous exceptions thrown during these callbacks bypass standard TLS error handling paths (tlsClientError and error), causing either immediate process termination or silent file descriptor leaks that eventually lead to denial of service. Because these callbacks process attacker-controlled input during the TLS handshake, a remote client can repeatedly trigger the issue. This vulnerability affects TLS servers using PSK or ALPN callbacks across Node.js versions where these callbacks throw without being safely wrapped.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-21637"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/december-2025-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/december-2025-security-releases"
        }
      ],
      "release_date": "2026-01-20T21:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-48931",
      "cwe": {
        "id": "CWE-367",
        "name": "Time-of-check Time-of-use (TOCTOU) Race Condition"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-48931"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2026/07/02/2",
          "url": "http://www.openwall.com/lists/oss-security/2026/07/02/2"
        },
        {
          "category": "external",
          "summary": "https://github.com/nodejs/node/issues/63989",
          "url": "https://github.com/nodejs/node/issues/63989"
        },
        {
          "category": "external",
          "summary": "https://jdstaerk.substack.com/p/nodejs-security-fix-silently-broke",
          "url": "https://jdstaerk.substack.com/p/nodejs-security-fix-silently-broke"
        }
      ],
      "release_date": "2026-06-22T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Low"
        }
      ]
    },
    {
      "cve": "CVE-2026-21714",
      "cwe": {
        "id": "CWE-401",
        "name": "Missing Release of Memory after Effective Lifetime"
      },
      "notes": [
        {
          "category": "description",
          "text": "A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up.\r\n\r\nThis vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-21714"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/march-2026-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/march-2026-security-releases"
        }
      ],
      "release_date": "2026-03-30T20:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2024-27982",
      "cwe": {
        "id": "CWE-444",
        "name": "Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')"
      },
      "notes": [
        {
          "category": "description",
          "text": "The team has identified a critical vulnerability in the http server of the most recent version of Node, where malformed headers can lead to HTTP request smuggling. Specifically, if a space is placed before a content-length header, it is not interpreted correctly, enabling attackers to smuggle in a second request within the body of the first.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2024-27982"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2237099",
          "url": "https://hackerone.com/reports/2237099"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html",
          "url": "https://lists.debian.org/debian-lts-announce/2024/09/msg00029.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JDECX4BYZLMM4S4LALN4DPZ2HUTTPLKE/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JDECX4BYZLMM4S4LALN4DPZ2HUTTPLKE/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QJAKA33NJCI3XLQS2K36DRCUMWIFFYVU/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/QJAKA33NJCI3XLQS2K36DRCUMWIFFYVU/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X4M5XZZONMS4DAZE3CNDFDRSB6JQCL6Y/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X4M5XZZONMS4DAZE3CNDFDRSB6JQCL6Y/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250418-0001/",
          "url": "https://security.netapp.com/advisory/ntap-20250418-0001/"
        }
      ],
      "release_date": "2024-05-07T17:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-48618",
      "cwe": {
        "id": "CWE-176",
        "name": "Improper Handling of Unicode Encoding"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat.\r\n\r\nThis can lead to confidentiality impact or bypass of the intended security boundary under affected configurations.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-48618"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:28727",
          "url": "https://access.redhat.com/errata/RHSA-2026:28727"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:29012",
          "url": "https://access.redhat.com/errata/RHSA-2026:29012"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:30172",
          "url": "https://access.redhat.com/errata/RHSA-2026:30172"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:35841",
          "url": "https://access.redhat.com/errata/RHSA-2026:35841"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:35842",
          "url": "https://access.redhat.com/errata/RHSA-2026:35842"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:35891",
          "url": "https://access.redhat.com/errata/RHSA-2026:35891"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:35892",
          "url": "https://access.redhat.com/errata/RHSA-2026:35892"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:39246",
          "url": "https://access.redhat.com/errata/RHSA-2026:39246"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:39868",
          "url": "https://access.redhat.com/errata/RHSA-2026:39868"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:41947",
          "url": "https://access.redhat.com/errata/RHSA-2026:41947"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:52399",
          "url": "https://access.redhat.com/errata/RHSA-2026:52399"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:7378",
          "url": "https://access.redhat.com/errata/RHSA-2026:7378"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/errata/RHSA-2026:9455",
          "url": "https://access.redhat.com/errata/RHSA-2026:9455"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/CVE-2026-48618",
          "url": "https://access.redhat.com/security/cve/CVE-2026-48618"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2493337",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2493337"
        },
        {
          "category": "external",
          "summary": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json",
          "url": "https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-48618.json"
        }
      ],
      "release_date": "2026-06-26T02:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2025-59466",
      "cwe": {
        "id": "CWE-248",
        "name": "Uncaught Exception"
      },
      "notes": [
        {
          "category": "description",
          "text": "We have identified a bug in Node.js error handling where \"Maximum call stack size exceeded\" errors become uncatchable when `async_hooks.createHook()` is enabled. Instead of reaching `process.on('uncaughtException')`, the process terminates, making the crash unrecoverable. Applications that rely on `AsyncLocalStorage` (v22, v20) or `async_hooks.createHook()` (v24, v22, v20) become vulnerable to denial-of-service crashes triggered by deep recursion under specific conditions.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2025-59466"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/december-2025-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/december-2025-security-releases"
        }
      ],
      "release_date": "2026-01-20T21:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2025-23085",
      "cwe": {
        "id": "CWE-401",
        "name": "Missing Release of Memory after Effective Lifetime"
      },
      "notes": [
        {
          "category": "description",
          "text": "A memory leak could occur when a remote peer abruptly closes the socket without sending a GOAWAY notification. Additionally, if an invalid header was detected by nghttp2, causing the connection to be terminated by the peer, the same leak was triggered. This flaw could lead to increased memory consumption and potential denial of service under certain conditions.\r\n\r\nThis vulnerability affects HTTP/2 Server users on Node.js v18.x, v20.x, v22.x and v23.x.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2025-23085"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/january-2025-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/january-2025-security-releases"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2025/02/msg00031.html",
          "url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00031.html"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20250321-0003/",
          "url": "https://security.netapp.com/advisory/ntap-20250321-0003/"
        }
      ],
      "release_date": "2025-02-07T07:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2023-44487",
      "notes": [
        {
          "category": "description",
          "text": "The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
          "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
          "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2023-44487"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2023/10/10/6",
          "url": "http://www.openwall.com/lists/oss-security/2023/10/10/6"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2023/10/10/7",
          "url": "http://www.openwall.com/lists/oss-security/2023/10/10/7"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2023/10/13/4",
          "url": "http://www.openwall.com/lists/oss-security/2023/10/13/4"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2023/10/13/9",
          "url": "http://www.openwall.com/lists/oss-security/2023/10/13/9"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2023/10/18/4",
          "url": "http://www.openwall.com/lists/oss-security/2023/10/18/4"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2023/10/18/8",
          "url": "http://www.openwall.com/lists/oss-security/2023/10/18/8"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2023/10/19/6",
          "url": "http://www.openwall.com/lists/oss-security/2023/10/19/6"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2023/10/20/8",
          "url": "http://www.openwall.com/lists/oss-security/2023/10/20/8"
        },
        {
          "category": "external",
          "summary": "https://access.redhat.com/security/cve/cve-2023-44487",
          "url": "https://access.redhat.com/security/cve/cve-2023-44487"
        },
        {
          "category": "external",
          "summary": "https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/",
          "url": "https://arstechnica.com/security/2023/10/how-ddosers-used-the-http-2-protocol-to-deliver-attacks-of-unprecedented-size/"
        },
        {
          "category": "external",
          "summary": "https://aws.amazon.com/security/security-bulletins/AWS-2023-011/",
          "url": "https://aws.amazon.com/security/security-bulletins/AWS-2023-011/"
        },
        {
          "category": "external",
          "summary": "https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/",
          "url": "https://blog.cloudflare.com/technical-breakdown-http2-rapid-reset-ddos-attack/"
        },
        {
          "category": "external",
          "summary": "https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/",
          "url": "https://blog.cloudflare.com/zero-day-rapid-reset-http2-record-breaking-ddos-attack/"
        },
        {
          "category": "external",
          "summary": "https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/",
          "url": "https://blog.litespeedtech.com/2023/10/11/rapid-reset-http-2-vulnerablilty/"
        },
        {
          "category": "external",
          "summary": "https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack",
          "url": "https://blog.qualys.com/vulnerabilities-threat-research/2023/10/10/cve-2023-44487-http-2-rapid-reset-attack"
        },
        {
          "category": "external",
          "summary": "https://blog.vespa.ai/cve-2023-44487/",
          "url": "https://blog.vespa.ai/cve-2023-44487/"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.proxmox.com/show_bug.cgi?id=4988",
          "url": "https://bugzilla.proxmox.com/show_bug.cgi?id=4988"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.redhat.com/show_bug.cgi?id=2242803",
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2242803"
        },
        {
          "category": "external",
          "summary": "https://bugzilla.suse.com/show_bug.cgi?id=1216123",
          "url": "https://bugzilla.suse.com/show_bug.cgi?id=1216123"
        },
        {
          "category": "external",
          "summary": "https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9",
          "url": "https://cgit.freebsd.org/ports/commit/?id=c64c329c2c1752f46b73e3e6ce9f4329be6629f9"
        },
        {
          "category": "external",
          "summary": "https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/",
          "url": "https://cloud.google.com/blog/products/identity-security/google-cloud-mitigated-largest-ddos-attack-peaking-above-398-million-rps/"
        },
        {
          "category": "external",
          "summary": "https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack",
          "url": "https://cloud.google.com/blog/products/identity-security/how-it-works-the-novel-http2-rapid-reset-ddos-attack"
        },
        {
          "category": "external",
          "summary": "https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125",
          "url": "https://community.traefik.io/t/is-traefik-vulnerable-to-cve-2023-44487/20125"
        },
        {
          "category": "external",
          "summary": "https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715",
          "url": "https://discuss.hashicorp.com/t/hcsec-2023-32-vault-consul-and-boundary-affected-by-http-2-rapid-reset-denial-of-service-vulnerability-cve-2023-44487/59715"
        },
        {
          "category": "external",
          "summary": "https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve",
          "url": "https://edg.io/lp/blog/resets-leaks-ddos-and-the-tale-of-a-hidden-cve"
        },
        {
          "category": "external",
          "summary": "https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764",
          "url": "https://forums.swift.org/t/swift-nio-http2-security-update-cve-2023-44487-http-2-dos/67764"
        },
        {
          "category": "external",
          "summary": "https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088",
          "url": "https://gist.github.com/adulau/7c2bfb8e9cdbe4b35a5e131c66a0c088"
        },
        {
          "category": "external",
          "summary": "https://github.com/Azure/AKS/issues/3947",
          "url": "https://github.com/Azure/AKS/issues/3947"
        },
        {
          "category": "external",
          "summary": "https://github.com/Kong/kong/discussions/11741",
          "url": "https://github.com/Kong/kong/discussions/11741"
        },
        {
          "category": "external",
          "summary": "https://github.com/advisories/GHSA-qppj-fm5r-hxr3",
          "url": "https://github.com/advisories/GHSA-qppj-fm5r-hxr3"
        },
        {
          "category": "external",
          "summary": "https://github.com/advisories/GHSA-vx74-f528-fxqg",
          "url": "https://github.com/advisories/GHSA-vx74-f528-fxqg"
        },
        {
          "category": "external",
          "summary": "https://github.com/advisories/GHSA-xpw8-rcwv-8f8p",
          "url": "https://github.com/advisories/GHSA-xpw8-rcwv-8f8p"
        },
        {
          "category": "external",
          "summary": "https://github.com/akka/akka-http/issues/4323",
          "url": "https://github.com/akka/akka-http/issues/4323"
        },
        {
          "category": "external",
          "summary": "https://github.com/alibaba/tengine/issues/1872",
          "url": "https://github.com/alibaba/tengine/issues/1872"
        },
        {
          "category": "external",
          "summary": "https://github.com/apache/apisix/issues/10320",
          "url": "https://github.com/apache/apisix/issues/10320"
        },
        {
          "category": "external",
          "summary": "https://github.com/apache/httpd-site/pull/10",
          "url": "https://github.com/apache/httpd-site/pull/10"
        },
        {
          "category": "external",
          "summary": "https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113",
          "url": "https://github.com/apache/httpd/blob/afcdbeebbff4b0c50ea26cdd16e178c0d1f24152/modules/http2/h2_mplx.c#L1101-L1113"
        },
        {
          "category": "external",
          "summary": "https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2",
          "url": "https://github.com/apache/tomcat/tree/main/java/org/apache/coyote/http2"
        },
        {
          "category": "external",
          "summary": "https://github.com/apache/trafficserver/pull/10564",
          "url": "https://github.com/apache/trafficserver/pull/10564"
        },
        {
          "category": "external",
          "summary": "https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487",
          "url": "https://github.com/arkrwn/PoC/tree/main/CVE-2023-44487"
        },
        {
          "category": "external",
          "summary": "https://github.com/bcdannyboy/CVE-2023-44487",
          "url": "https://github.com/bcdannyboy/CVE-2023-44487"
        },
        {
          "category": "external",
          "summary": "https://github.com/caddyserver/caddy/issues/5877",
          "url": "https://github.com/caddyserver/caddy/issues/5877"
        },
        {
          "category": "external",
          "summary": "https://github.com/caddyserver/caddy/releases/tag/v2.7.5",
          "url": "https://github.com/caddyserver/caddy/releases/tag/v2.7.5"
        },
        {
          "category": "external",
          "summary": "https://github.com/dotnet/announcements/issues/277",
          "url": "https://github.com/dotnet/announcements/issues/277"
        },
        {
          "category": "external",
          "summary": "https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73",
          "url": "https://github.com/dotnet/core/blob/e4613450ea0da7fd2fc6b61dfb2c1c1dec1ce9ec/release-notes/6.0/6.0.23/6.0.23.md?plain=1#L73"
        },
        {
          "category": "external",
          "summary": "https://github.com/eclipse/jetty.project/issues/10679",
          "url": "https://github.com/eclipse/jetty.project/issues/10679"
        },
        {
          "category": "external",
          "summary": "https://github.com/envoyproxy/envoy/pull/30055",
          "url": "https://github.com/envoyproxy/envoy/pull/30055"
        },
        {
          "category": "external",
          "summary": "https://github.com/etcd-io/etcd/issues/16740",
          "url": "https://github.com/etcd-io/etcd/issues/16740"
        },
        {
          "category": "external",
          "summary": "https://github.com/facebook/proxygen/pull/466",
          "url": "https://github.com/facebook/proxygen/pull/466"
        },
        {
          "category": "external",
          "summary": "https://github.com/golang/go/issues/63417",
          "url": "https://github.com/golang/go/issues/63417"
        },
        {
          "category": "external",
          "summary": "https://github.com/grpc/grpc-go/pull/6703",
          "url": "https://github.com/grpc/grpc-go/pull/6703"
        },
        {
          "category": "external",
          "summary": "https://github.com/grpc/grpc/releases/tag/v1.59.2",
          "url": "https://github.com/grpc/grpc/releases/tag/v1.59.2"
        },
        {
          "category": "external",
          "summary": "https://github.com/h2o/h2o/pull/3291",
          "url": "https://github.com/h2o/h2o/pull/3291"
        },
        {
          "category": "external",
          "summary": "https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf",
          "url": "https://github.com/h2o/h2o/security/advisories/GHSA-2m7v-gc89-fjqf"
        },
        {
          "category": "external",
          "summary": "https://github.com/haproxy/haproxy/issues/2312",
          "url": "https://github.com/haproxy/haproxy/issues/2312"
        },
        {
          "category": "external",
          "summary": "https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244",
          "url": "https://github.com/icing/mod_h2/blob/0a864782af0a942aa2ad4ed960a6b32cd35bcf0a/mod_http2/README.md?plain=1#L239-L244"
        },
        {
          "category": "external",
          "summary": "https://github.com/junkurihara/rust-rpxy/issues/97",
          "url": "https://github.com/junkurihara/rust-rpxy/issues/97"
        },
        {
          "category": "external",
          "summary": "https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1",
          "url": "https://github.com/kazu-yamamoto/http2/commit/f61d41a502bd0f60eb24e1ce14edc7b6df6722a1"
        },
        {
          "category": "external",
          "summary": "https://github.com/kazu-yamamoto/http2/issues/93",
          "url": "https://github.com/kazu-yamamoto/http2/issues/93"
        },
        {
          "category": "external",
          "summary": "https://github.com/kubernetes/kubernetes/pull/121120",
          "url": "https://github.com/kubernetes/kubernetes/pull/121120"
        },
        {
          "category": "external",
          "summary": "https://github.com/line/armeria/pull/5232",
          "url": "https://github.com/line/armeria/pull/5232"
        },
        {
          "category": "external",
          "summary": "https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632",
          "url": "https://github.com/linkerd/website/pull/1695/commits/4b9c6836471bc8270ab48aae6fd2181bc73fd632"
        },
        {
          "category": "external",
          "summary": "https://github.com/micrictor/http2-rst-stream",
          "url": "https://github.com/micrictor/http2-rst-stream"
        },
        {
          "category": "external",
          "summary": "https://github.com/microsoft/CBL-Mariner/pull/6381",
          "url": "https://github.com/microsoft/CBL-Mariner/pull/6381"
        },
        {
          "category": "external",
          "summary": "https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61",
          "url": "https://github.com/netty/netty/commit/58f75f665aa81a8cbcf6ffa74820042a285c5e61"
        },
        {
          "category": "external",
          "summary": "https://github.com/nghttp2/nghttp2/pull/1961",
          "url": "https://github.com/nghttp2/nghttp2/pull/1961"
        },
        {
          "category": "external",
          "summary": "https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0",
          "url": "https://github.com/nghttp2/nghttp2/releases/tag/v1.57.0"
        },
        {
          "category": "external",
          "summary": "https://github.com/ninenines/cowboy/issues/1615",
          "url": "https://github.com/ninenines/cowboy/issues/1615"
        },
        {
          "category": "external",
          "summary": "https://github.com/nodejs/node/pull/50121",
          "url": "https://github.com/nodejs/node/pull/50121"
        },
        {
          "category": "external",
          "summary": "https://github.com/openresty/openresty/issues/930",
          "url": "https://github.com/openresty/openresty/issues/930"
        },
        {
          "category": "external",
          "summary": "https://github.com/opensearch-project/data-prepper/issues/3474",
          "url": "https://github.com/opensearch-project/data-prepper/issues/3474"
        },
        {
          "category": "external",
          "summary": "https://github.com/oqtane/oqtane.framework/discussions/3367",
          "url": "https://github.com/oqtane/oqtane.framework/discussions/3367"
        },
        {
          "category": "external",
          "summary": "https://github.com/projectcontour/contour/pull/5826",
          "url": "https://github.com/projectcontour/contour/pull/5826"
        },
        {
          "category": "external",
          "summary": "https://github.com/tempesta-tech/tempesta/issues/1986",
          "url": "https://github.com/tempesta-tech/tempesta/issues/1986"
        },
        {
          "category": "external",
          "summary": "https://github.com/varnishcache/varnish-cache/issues/3996",
          "url": "https://github.com/varnishcache/varnish-cache/issues/3996"
        },
        {
          "category": "external",
          "summary": "https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo",
          "url": "https://groups.google.com/g/golang-announce/c/iNNxDTCjZvo"
        },
        {
          "category": "external",
          "summary": "https://istio.io/latest/news/security/istio-security-2023-004/",
          "url": "https://istio.io/latest/news/security/istio-security-2023-004/"
        },
        {
          "category": "external",
          "summary": "https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/",
          "url": "https://linkerd.io/2023/10/12/linkerd-cve-2023-44487/"
        },
        {
          "category": "external",
          "summary": "https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q",
          "url": "https://lists.apache.org/thread/5py8h42mxfsn8l1wy6o41xwhsjlsd87q"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00020.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00023.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00024.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00045.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/10/msg00047.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00001.html"
        },
        {
          "category": "external",
          "summary": "https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html",
          "url": "https://lists.debian.org/debian-lts-announce/2023/11/msg00012.html"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/"
        },
        {
          "category": "external",
          "summary": "https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html",
          "url": "https://lists.w3.org/Archives/Public/ietf-http-wg/2023OctDec/0025.html"
        },
        {
          "category": "external",
          "summary": "https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html",
          "url": "https://mailman.nginx.org/pipermail/nginx-devel/2023-October/S36Q5HBXR7CAIMPLLPRSSSYR4PCMWILK.html"
        },
        {
          "category": "external",
          "summary": "https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html",
          "url": "https://martinthomson.github.io/h2-stream-limits/draft-thomson-httpbis-h2-stream-limits.html"
        },
        {
          "category": "external",
          "summary": "https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/",
          "url": "https://msrc.microsoft.com/blog/2023/10/microsoft-response-to-distributed-denial-of-service-ddos-attacks-against-http/2/"
        },
        {
          "category": "external",
          "summary": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487",
          "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-44487"
        },
        {
          "category": "external",
          "summary": "https://my.f5.com/manage/s/article/K000137106",
          "url": "https://my.f5.com/manage/s/article/K000137106"
        },
        {
          "category": "external",
          "summary": "https://netty.io/news/2023/10/10/4-1-100-Final.html",
          "url": "https://netty.io/news/2023/10/10/4-1-100-Final.html"
        },
        {
          "category": "external",
          "summary": "https://news.ycombinator.com/item?id=37830987",
          "url": "https://news.ycombinator.com/item?id=37830987"
        },
        {
          "category": "external",
          "summary": "https://news.ycombinator.com/item?id=37830998",
          "url": "https://news.ycombinator.com/item?id=37830998"
        },
        {
          "category": "external",
          "summary": "https://news.ycombinator.com/item?id=37831062",
          "url": "https://news.ycombinator.com/item?id=37831062"
        },
        {
          "category": "external",
          "summary": "https://news.ycombinator.com/item?id=37837043",
          "url": "https://news.ycombinator.com/item?id=37837043"
        },
        {
          "category": "external",
          "summary": "https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/",
          "url": "https://openssf.org/blog/2023/10/10/http-2-rapid-reset-vulnerability-highlights-need-for-rapid-response/"
        },
        {
          "category": "external",
          "summary": "https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected",
          "url": "https://seanmonstar.com/post/730794151136935936/hyper-http2-rapid-reset-unaffected"
        },
        {
          "category": "external",
          "summary": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ",
          "url": "https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-http2-reset-d8Kf32vZ"
        },
        {
          "category": "external",
          "summary": "https://security.gentoo.org/glsa/202311-09",
          "url": "https://security.gentoo.org/glsa/202311-09"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20231016-0001/",
          "url": "https://security.netapp.com/advisory/ntap-20231016-0001/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20240426-0007/",
          "url": "https://security.netapp.com/advisory/ntap-20240426-0007/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20240621-0006/",
          "url": "https://security.netapp.com/advisory/ntap-20240621-0006/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20240621-0007/",
          "url": "https://security.netapp.com/advisory/ntap-20240621-0007/"
        },
        {
          "category": "external",
          "summary": "https://security.paloaltonetworks.com/CVE-2023-44487",
          "url": "https://security.paloaltonetworks.com/CVE-2023-44487"
        },
        {
          "category": "external",
          "summary": "https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14",
          "url": "https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.14"
        },
        {
          "category": "external",
          "summary": "https://ubuntu.com/security/CVE-2023-44487",
          "url": "https://ubuntu.com/security/CVE-2023-44487"
        },
        {
          "category": "external",
          "summary": "https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/",
          "url": "https://www.bleepingcomputer.com/news/security/new-http-2-rapid-reset-zero-day-attack-breaks-ddos-records/"
        },
        {
          "category": "external",
          "summary": "https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487",
          "url": "https://www.cisa.gov/news-events/alerts/2023/10/10/http2-rapid-reset-vulnerability-cve-2023-44487"
        },
        {
          "category": "external",
          "summary": "https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event",
          "url": "https://www.darkreading.com/cloud/internet-wide-zero-day-bug-fuels-largest-ever-ddos-event"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2023/dsa-5521",
          "url": "https://www.debian.org/security/2023/dsa-5521"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2023/dsa-5522",
          "url": "https://www.debian.org/security/2023/dsa-5522"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2023/dsa-5540",
          "url": "https://www.debian.org/security/2023/dsa-5540"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2023/dsa-5549",
          "url": "https://www.debian.org/security/2023/dsa-5549"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2023/dsa-5558",
          "url": "https://www.debian.org/security/2023/dsa-5558"
        },
        {
          "category": "external",
          "summary": "https://www.debian.org/security/2023/dsa-5570",
          "url": "https://www.debian.org/security/2023/dsa-5570"
        },
        {
          "category": "external",
          "summary": "https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487",
          "url": "https://www.haproxy.com/blog/haproxy-is-not-affected-by-the-http-2-rapid-reset-attack-cve-2023-44487"
        },
        {
          "category": "external",
          "summary": "https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/",
          "url": "https://www.netlify.com/blog/netlify-successfully-mitigates-cve-2023-44487/"
        },
        {
          "category": "external",
          "summary": "https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/",
          "url": "https://www.nginx.com/blog/http-2-rapid-reset-attack-impacting-f5-nginx-products/"
        },
        {
          "category": "external",
          "summary": "https://www.openwall.com/lists/oss-security/2023/10/10/6",
          "url": "https://www.openwall.com/lists/oss-security/2023/10/10/6"
        },
        {
          "category": "external",
          "summary": "https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack",
          "url": "https://www.phoronix.com/news/HTTP2-Rapid-Reset-Attack"
        },
        {
          "category": "external",
          "summary": "https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/",
          "url": "https://www.theregister.com/2023/10/10/http2_rapid_reset_zeroday/"
        },
        {
          "category": "external",
          "summary": "http://www.openwall.com/lists/oss-security/2025/08/13/6",
          "url": "http://www.openwall.com/lists/oss-security/2025/08/13/6"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2MBEPPC36UBVOZZNAXFHKLFGSLCMN5LI/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3N4NJ7FR4X4FPZUGNTQAPSTVB2HB2Y4A/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/BFQD3KUEMFBHPAPBGLWQC34L4OWL5HAZ/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CLB4TW7KALB3EEQWNWCN7OUIWWVWWCG2/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/E72T67UPDRXHIDLO3OROR25YAMN4GGW5/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FNA62Q767CFAFHBCDKYNPBMZWB7TWYVU/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/HT7T2R4MQKLIF4ODV4BDLPARWFPCJ5CZ/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JIZSEFC3YKCGABA2BZW6ZJRMDZJMB7PJ/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JMEXY22BFG5Q64HQCM5CK2Q7KDKVV4TY/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KSEGD2IWKNUO3DWY4KQGUQM5BISRWHQE/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LKYHSZQFDNR7RSA7LHVLLIAQMVYCUGBG/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LNMZJCDHGLJJLXO4OXWJMTVQRNWOC7UL/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VHUHTSXLXGXS7JYKBXTA3VINUPHTNGVU/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VSRDIV77HNKUSM7SJC5BKE5JSHLHU2NK/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WE2I52RHNNU42PX6NZ2RBUHSFFJ2LVZX/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WLPRQ5TWUQQXYWBJM7ECYDAIL2YVKIUH/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/X6QXN4ORIVF6XBW4WWFE7VNPVC74S45Y/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/XFOIBB4YFICHDM7IBOP7PWXW3FX4HLL2/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZB43REMKRQR62NJEI7I5NQ4FSXNLBKRT/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZKQSIKIAT5TJ3WSLU3RDBQ35YX4GY4V3/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZLU6U2R2IC2K64NDPNMV55AUAO65MAF4/"
        },
        {
          "category": "external",
          "summary": "https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-understanding-the-root-cause",
          "url": "https://www.vicarius.io/vsociety/posts/rapid-reset-cve-2023-44487-dos-in-http2-understanding-the-root-cause"
        },
        {
          "category": "external",
          "summary": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html",
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-082556.html"
        },
        {
          "category": "external",
          "summary": "https://cert-portal.siemens.com/productcert/html/ssa-341067.html",
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-341067.html"
        },
        {
          "category": "external",
          "summary": "https://cert-portal.siemens.com/productcert/html/ssa-784301.html",
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-784301.html"
        },
        {
          "category": "external",
          "summary": "https://cert-portal.siemens.com/productcert/html/ssa-832273.html",
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-832273.html"
        },
        {
          "category": "external",
          "summary": "https://cert-portal.siemens.com/productcert/html/ssa-915275.html",
          "url": "https://cert-portal.siemens.com/productcert/html/ssa-915275.html"
        },
        {
          "category": "external",
          "summary": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44487",
          "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-44487"
        }
      ],
      "release_date": "2023-10-10T14:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-02T22:58:45.075608Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923",
          "product_ids": [
            "CentOS-6:alt-nodejs12-nodejs-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-devel-0:12.22.12-29.el6.x86_64",
            "CentOS-6:alt-nodejs12-nodejs-docs-0:12.22.12-29.el6.noarch",
            "CentOS-6:alt-nodejs12-npm-1:6.14.16-12.22.12.29.el6.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1788389923"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}