-
released this
2026-07-07 11:36:32 +00:00 | 6 commits to c10s since this releaseResolves: RHEL-183886
Resolves: RHEL-189398
Resolves: RHEL-189348
Resolves: RHEL-185997
Resolves: RHEL-185984
Resolves: RHEL-185978
Resolves: RHEL-183655CVE fixes included in rebase:
CVE-2026-48618 - tls: normalize hostname for server identity checks
CVE-2026-48933 - crypto: guard WebCrypto cipher output length
CVE-2026-6734 - undici vulnerable to cross-origin request routing via SOCKS5 proxy pool reuse
Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-hm92-r4w5-c3mj
CVE-2026-9697 - undici vulnerable to TLS certificate validation bypass via
dropped requestTls in SOCKS5 ProxyAgent
Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g
CVE-2026-12151 - undici WebSocket client vulnerable to denial of service via fragment count bypass
Advisory: https://github.com/nodejs/undici/security/advisories/GHSA-vmh5-mc38-953g
CVE-2026-42338 - ip-address: Cross-site scripting via improper HTML escaping of untrusted inputAlso following CVEs with lower severity:
CVE-2026-48615, CVE-2026-48619, CVE-2026-48928, CVE-2026-48930, CVE-2026-48934
CVE-2026-48937, CVE-2026-48617, CVE-2026-48931, CVE-2026-48935Drop downstream nghttp2 patch
Downloads
-
Source code (ZIP)
0 downloads
-
Source code (TAR.GZ)
0 downloads
-
Source code (ZIP)