{"id":"MGASA-2016-0080","summary":"Updated nodejs packages fix security vulnerability","details":"A request smuggling vulnerability was found in Node.js that can be\nexploited under certain unspecified circumstances (CVE-2016-2086).\n\nIt was reported that HTTP header parsing in Node.js is vulnerable to\nresponse splitting attacks. While Node.js has been protecting against\nresponse splitting attacks by checking for CRLF characters, it is possible\nto compose response headers using Unicode characters that decompose to\nthese characters, bypassing the checks previously in place\n(CVE-2016-2216).\n","modified":"2026-04-16T06:24:03.986811648Z","published":"2016-02-19T08:40:43Z","upstream":["CVE-2016-2086","CVE-2016-2216"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2016-0080.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=17779"},{"type":"WEB","url":"https://nodejs.org/en/blog/release/v0.10.42/"},{"type":"WEB","url":"https://nodejs.org/en/blog/vulnerability/february-2016-security-releases/"},{"type":"WEB","url":"https://lists.fedoraproject.org/pipermail/package-announce/2016-February/177184.html"}],"affected":[{"package":{"name":"nodejs","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/nodejs?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.42-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2016-0080.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}