{
  "document": {
    "aggregate_severity": {
      "text": "Critical"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "CVE-2026-48619: cap HTTP/2 client originSet size to prevent unbounded\n  memory growth from malicious ORIGIN frames\n- CVE-2026-48930: reject dns/net hostnames with embedded NUL bytes to\n  prevent silent authority rebinding via C-string truncation\n- CVE-2026-48933: guard WebCrypto cipher output length to avoid signed\n  integer overflow on ~2 GiB inputs",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153",
        "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_alt_nodejs/el10/advisories/2026/clsa-2026_1783425153.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-29T14:54:32Z",
      "generator": {
        "date": "2026-07-29T14:54:32Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1783425153",
      "initial_release_date": "2026-07-07T11:53:38Z",
      "revision_history": [
        {
          "date": "2026-07-07T11:53:38Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-29T14:54:32Z",
          "number": "2",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "2"
    },
    "title": "alt-nodejs20-nodejs: Fix of 3 CVEs"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 10",
                "product": {
                  "name": "Community Enterprise Operating System 10",
                  "product_id": "CentOS-10",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:10:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          }
        ],
        "category": "vendor",
        "name": "Cloud Linux Software, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
                "product": {
                  "name": "alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
                  "product_id": "alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-nodejs20-nodejs-docs@20.20.2-3.el10?arch=noarch&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
                "product": {
                  "name": "alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
                  "product_id": "alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-nodejs20-nodejs-docs@20.20.2-2.el10?arch=noarch&os_name=centos&os_version=10"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "noarch"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64",
                "product": {
                  "name": "alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64",
                  "product_id": "alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-nodejs20-npm@10.8.2-20.20.2.3.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
                "product": {
                  "name": "alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
                  "product_id": "alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-nodejs20-nodejs-devel@20.20.2-3.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
                "product": {
                  "name": "alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
                  "product_id": "alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-nodejs20-nodejs@20.20.2-3.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
                "product": {
                  "name": "alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
                  "product_id": "alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-nodejs20-nodejs@20.20.2-2.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64",
                "product": {
                  "name": "alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64",
                  "product_id": "alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-nodejs20-npm@10.8.2-20.20.2.2.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
                "product": {
                  "name": "alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
                  "product_id": "alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/alt-nodejs20-nodejs-devel@20.20.2-2.el10?arch=x86_64&os_name=centos&os_version=10"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch"
        },
        "product_reference": "alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
        },
        "product_reference": "alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64"
        },
        "product_reference": "alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64"
        },
        "product_reference": "alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch"
        },
        "product_reference": "alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64"
        },
        "product_reference": "alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
        },
        "product_reference": "alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64 as a component of Community Enterprise Operating System 10",
          "product_id": "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64"
        },
        "product_reference": "alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
        "relates_to_product_reference": "CentOS-10"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-32003",
      "cwe": {
        "id": "CWE-22",
        "name": "Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')"
      },
      "notes": [
        {
          "category": "description",
          "text": "`fs.mkdtemp()` and `fs.mkdtempSync()` can be used to bypass the permission model check using a path traversal attack. This flaw arises from a missing check in the fs.mkdtemp() API and the impact is a malicious actor could create an arbitrary directory.\n\nThis vulnerability affects all users using the experimental permission model in Node.js 20.\n\nPlease note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
          "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
        ],
        "known_affected": [
          "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
          "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2023-32003"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2037887",
          "url": "https://hackerone.com/reports/2037887"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JQPELKG2LVTADSB7ME73AV4DXQK47PWK/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JQPELKG2LVTADSB7ME73AV4DXQK47PWK/"
        },
        {
          "category": "external",
          "summary": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PBOZE2QZIBLFFTYWYN23FGKN6HULZ6HX/",
          "url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PBOZE2QZIBLFFTYWYN23FGKN6HULZ6HX/"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20230915-0009/",
          "url": "https://security.netapp.com/advisory/ntap-20230915-0009/"
        }
      ],
      "release_date": "2023-08-15T16:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T11:52:36.704343Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153",
          "product_ids": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153"
        },
        {
          "category": "none_available",
          "date": "2023-08-15T16:15:00Z",
          "details": "Affected",
          "product_ids": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-48933",
      "cwe": {
        "id": "CWE-770",
        "name": "Allocation of Resources Without Limits or Throttling"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB.\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
          "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
        ],
        "known_affected": [
          "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
          "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-48933"
        }
      ],
      "release_date": "2026-06-26T02:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T11:52:36.704343Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153",
          "product_ids": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153"
        },
        {
          "category": "none_available",
          "date": "2026-06-26T02:16:00Z",
          "details": "Affected",
          "product_ids": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2026-48930",
      "cwe": {
        "id": "CWE-284",
        "name": "Improper Access Control"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
          "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
        ],
        "known_affected": [
          "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
          "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-48930"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases"
        }
      ],
      "release_date": "2026-06-26T02:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T11:52:36.704343Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153",
          "product_ids": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153"
        },
        {
          "category": "none_available",
          "date": "2026-06-26T02:16:00Z",
          "details": "Affected",
          "product_ids": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 9.8,
            "baseSeverity": "CRITICAL",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "products": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2023-30582",
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument. This flaw arises from an inadequate permission model that fails to restrict file watching through the fs.watchFile API. As a result, malicious actors can monitor files that they do not have explicit read access to.\nPlease note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
          "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
        ],
        "known_affected": [
          "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
          "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2023-30582"
        }
      ],
      "release_date": "2023-06-20T00:00:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T11:52:36.704343Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153",
          "product_ids": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153"
        },
        {
          "category": "none_available",
          "date": "2023-06-20T00:00:00Z",
          "details": "Affected",
          "product_ids": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "NONE",
            "integrityImpact": "LOW",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N",
            "version": "3.1"
          },
          "products": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    },
    {
      "cve": "CVE-2026-48619",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "notes": [
        {
          "category": "description",
          "text": "A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
          "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
        ],
        "known_affected": [
          "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
          "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2026-48619"
        },
        {
          "category": "external",
          "summary": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases",
          "url": "https://nodejs.org/en/blog/vulnerability/june-2026-security-releases"
        }
      ],
      "release_date": "2026-06-26T02:16:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T11:52:36.704343Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153",
          "product_ids": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153"
        },
        {
          "category": "none_available",
          "date": "2026-06-26T02:16:00Z",
          "details": "Affected",
          "product_ids": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 7.5,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "NONE",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "version": "3.1"
          },
          "products": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    },
    {
      "cve": "CVE-2024-37372",
      "notes": [
        {
          "category": "description",
          "text": "Permission model improperly processes UNC paths\n",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
          "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
        ],
        "known_affected": [
          "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
          "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2024-37372"
        }
      ],
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T11:52:36.704343Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153",
          "product_ids": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153"
        },
        {
          "category": "none_available",
          "details": "Affected",
          "product_ids": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Critical"
        }
      ]
    },
    {
      "cve": "CVE-2023-32005",
      "cwe": {
        "id": "CWE-732",
        "name": "Incorrect Permission Assignment for Critical Resource"
      },
      "notes": [
        {
          "category": "description",
          "text": "A vulnerability has been identified in Node.js version 20, affecting users of the experimental permission model when the --allow-fs-read flag is used with a non-* argument.\n\nThis flaw arises from an inadequate permission model that fails to restrict file stats through the `fs.statfs` API. As a result, malicious actors can retrieve stats from files that they do not have explicit read access to.\n\nThis vulnerability affects all users using the experimental permission model in Node.js 20.\n\nPlease note that at the time this CVE was issued, the permission model is an experimental feature of Node.js.",
          "title": "Vulnerability description"
        },
        {
          "category": "general",
          "text": "The CVSS score(s) listed for this vulnerability do not reflect the associated product's status, and are included for informational purposes to better understand the severity of this vulnerability.",
          "title": "CVSS score applicability"
        }
      ],
      "product_status": {
        "fixed": [
          "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
          "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
        ],
        "known_affected": [
          "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
          "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
          "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els-alt-nodejs/cve/CVE-2023-32005"
        },
        {
          "category": "external",
          "summary": "https://hackerone.com/reports/2051224",
          "url": "https://hackerone.com/reports/2051224"
        },
        {
          "category": "external",
          "summary": "https://security.netapp.com/advisory/ntap-20231103-0004/",
          "url": "https://security.netapp.com/advisory/ntap-20231103-0004/"
        }
      ],
      "release_date": "2023-09-12T02:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-07-07T11:52:36.704343Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153",
          "product_ids": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
          ],
          "url": "https://cve.tuxcare.com/els-alt-nodejs/releases/CLSA-2026:1783425153"
        },
        {
          "category": "none_available",
          "date": "2023-09-12T02:15:00Z",
          "details": "Affected",
          "product_ids": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-2.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-2.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-2.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.2.el10.x86_64"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 5.3,
            "baseSeverity": "MEDIUM",
            "confidentialityImpact": "LOW",
            "integrityImpact": "NONE",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
            "version": "3.1"
          },
          "products": [
            "CentOS-10:alt-nodejs20-nodejs-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-devel-0:20.20.2-3.el10.x86_64",
            "CentOS-10:alt-nodejs20-nodejs-docs-0:20.20.2-3.el10.noarch",
            "CentOS-10:alt-nodejs20-npm-0:10.8.2-20.20.2.3.el10.x86_64"
          ]
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Moderate"
        }
      ]
    }
  ]
}