[CLSA-2026:1788259355] alt-nodejs18-nodejs: Fix of CVE-2026-58040
Type:
security
Severity:
Moderate
Release date:
2026-09-01 10:42:45 UTC
Description:
- ALTNJS-278: stop depending on the SCL-scoped alt-nodejs18-zlib collection. On CL7 node is now built against its bundled deps/zlib, because the base OS zlib 1.2.7 makes npm fail with Z_DATA_ERROR while inflating registry responses. Other platforms keep linking the system zlib as before. - ALTNJS-278: BuildRequire the SCL runtime explicitly on el7; it used to arrive transitively through alt-nodejs18-zlib-devel.
CVEs fixed:
Updated packages:
  • alt-nodejs18-nodejs-18.20.8-20.el9.x86_64.rpm
    sha:64fcab739e7d93c919d121029616cb78a0bd17a556d34037abd645ef6321c8e1
  • alt-nodejs18-nodejs-devel-18.20.8-20.el9.x86_64.rpm
    sha:8a886286f42b528251cdbe1dd0984a1c14a934631d6fa398b3b0f44e5929f6d1
  • alt-nodejs18-nodejs-docs-18.20.8-20.el9.noarch.rpm
    sha:bfc1ac7042628e93ba29b4222436abc5905980e7f21daa9a257aa57c83fc3a29
  • alt-nodejs18-npm-10.8.2-18.20.8.20.el9.x86_64.rpm
    sha:9ff5f08070e951862f727a9525d1a550a3d898b730b64d54e9614598d1530533
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.