vulnerability
Alma Linux: CVE-2023-24807: Moderate: nodejs:16 security, bug fix, and enhancement update (Multiple Advisories)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 8 | (AV:N/AC:L/Au:N/C:N/I:N/A:C) | Feb 16, 2023 | Apr 21, 2023 | Apr 17, 2026 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
Feb 16, 2023
Added
Apr 21, 2023
Modified
Apr 17, 2026
Description
Undici is an HTTP/1.1 client for Node.js. Prior to version 5.19.1, the `Headers.set()` and `Headers.append()` methods are vulnerable to Regular Expression Denial of Service (ReDoS) attacks when untrusted values are passed into the functions. This is due to the inefficient regular expression used to normalize the values in the `headerValueNormalize()` utility function. This vulnerability was patched in v5.19.1. No known workarounds are available.
Solutions
alma-upgrade-nodejsalma-upgrade-nodejs-develalma-upgrade-nodejs-docsalma-upgrade-nodejs-full-i18nalma-upgrade-nodejs-libsalma-upgrade-nodejs-nodemonalma-upgrade-nodejs-packagingalma-upgrade-nodejs-packaging-bundleralma-upgrade-npm
References
- CVE-2023-24807
- https://attackerkb.com/topics/CVE-2023-24807
- CWE-1333
- CWE-20
- EUVD-EUVD-2023-0786
- https://errata.almalinux.org/8/ALSA-2023-1582.html
- https://errata.almalinux.org/8/ALSA-2023-1583.html
- https://errata.almalinux.org/9/ALSA-2023-2654.html
- https://errata.almalinux.org/9/ALSA-2023-2655.html
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0786
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.