Release date:
2026-09-08 08:27:47 UTC
Description:
- CVE-2022-43548: harden the inspector IsIPAddress() to parse IPv4 and bracketed
IPv6 hosts with uv_inet_pton(), rejecting octal, hexadecimal and leading-zero
octet formats and treating 0.0.0.0/8 and ::/128 as non-routable, closing the
--inspect DNS-rebinding host allow-list bypass
- Folded in upstream follow-up 73fa9ab7a5, which keeps the IPv6 string
terminator inside the INET6_ADDRSTRLEN buffer
Updated packages:
-
alt-nodejs12-nodejs-12.22.12-31.el6.x86_64.rpm
sha:d204fb56a79d25727f2b56dec82dc8b9eb75ff0ae90e0799019b01c641d159ac
-
alt-nodejs12-nodejs-devel-12.22.12-31.el6.x86_64.rpm
sha:38c7bff53d6b53f026488d984398e60b88ec83ad07838943feffef067f588320
-
alt-nodejs12-nodejs-docs-12.22.12-31.el6.noarch.rpm
sha:b455f495a37f5ab870fd011b9f56f3801f13fc7a9addc253d8fee1e08f9b6164
-
alt-nodejs12-npm-6.14.16-12.22.12.31.el6.x86_64.rpm
sha:c82a130eb8f965e106c07dd9640564fedc190fb7257ba32f4529bdc274a92916
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.