[CLSA-2026:1780263040] Fix CVE(s): CVE-2026-21717
Type:
security
Severity:
Moderate
Release date:
2026-05-31 21:30:53 UTC
Description:
* SECURITY UPDATE: HashDoS via V8 array-index hash collisions - debian/patches/CVE-2026-21717.patch: scramble V8 array-index hash_field with a 3-round xorshift-multiply so consecutive numeric strings no longer hash to consecutive buckets, preventing O(n^2) HashDoS via JSON.parse - CVE-2026-21717
CVEs fixed:
Updated packages:
  • alt-nodejs12-docs_12.22.12-21_amd64.deb
    sha:9ba3a57fd1217b1e7b4c91776e3de6c7de04831a
  • alt-nodejs12-nodejs_12.22.12-21_amd64.deb
    sha:843e4d4e8ccd2bc81b4ae6dcb6962ac9b0139c6a
  • alt-nodejs12-nodejs-devel_12.22.12-21_amd64.deb
    sha:925e5bb3859d2f0cc927e493847e5a68864ae925
  • alt-nodejs12-npm_6.14.16-12.22.12.21_amd64.deb
    sha:f0d27c4f96ef652b1be6bc3f49d39738937b94da
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.