[CLSA-2026:1788259615] alt-nodejs18-nodejs: Fix of CVE-2026-58040
Type:
security
Severity:
Moderate
Release date:
2026-09-01 10:47:06 UTC
Description:
- ALTNJS-278: stop depending on the SCL-scoped alt-nodejs18-zlib collection. On CL7 node is now built against its bundled deps/zlib, because the base OS zlib 1.2.7 makes npm fail with Z_DATA_ERROR while inflating registry responses. Other platforms keep linking the system zlib as before. - ALTNJS-278: BuildRequire the SCL runtime explicitly on el7; it used to arrive transitively through alt-nodejs18-zlib-devel.
CVEs fixed:
Updated packages:
  • alt-nodejs18-nodejs-18.20.8-20.el8.x86_64.rpm
    sha:00f5b0f6298239a2a09b9fc17eb86d60636b902001f6447800cb5f205cadd084
  • alt-nodejs18-nodejs-devel-18.20.8-20.el8.x86_64.rpm
    sha:3ef4cde600becb7c658be5e128033cd22e0ae3293b9c170d885033c8d2006593
  • alt-nodejs18-nodejs-docs-18.20.8-20.el8.noarch.rpm
    sha:8feb202dd5cd7c1a44a1185b4952ee4a0259e66d94ee08e557d94643fc5c17b4
  • alt-nodejs18-npm-10.8.2-18.20.8.20.el8.x86_64.rpm
    sha:9349a4d6de73ae251651620aa46d20a6cb24d40222a8bda318c66d581c6571fa
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.