ea-nodejs18 (18.20.6-1+2.1.cpanel) stable; urgency=low

  * EA-12662: Update ea-nodejs18 from v18.20.5 to v18.20.6
  * GOAWAY HTTP/2 frames cause memory leak outside heap (CVE-2025-23085) - (medium)
  * Path traversal by drive name in Windows environment (CVE-2025-23084) - (medium)

 -- Cory McIntire <cory@cpanel.net>  Tue, 21 Jan 2025 00:00:00 -0000

ea-nodejs18 (18.20.5-1) stable; urgency=low

  * EA-12552: Update ea-nodejs18 from v18.20.4 to v18.20.5

 -- Cory McIntire <cory@cpanel.net>  Fri, 15 Nov 2024 00:00:00 -0000

ea-nodejs18 (18.20.4-1) stable; urgency=low

  * EA-12274: Update ea-nodejs18 from v18.20.3 to v18.20.4
  * CVE-2024-36138 - Bypass incomplete fix of CVE-2024-27980 (High)
  * CVE-2024-22020 - Bypass network import restriction via data URL (Medium)

 -- Cory McIntire <cory@cpanel.net>  Tue, 09 Jul 2024 00:00:00 -0000

ea-nodejs18 (18.20.3-1) stable; urgency=low

  * EA-12166: Update ea-nodejs18 from v18.20.2 to v18.20.3

 -- Cory McIntire <cory@cpanel.net>  Tue, 21 May 2024 00:00:00 -0000

ea-nodejs18 (18.20.2-1) stable; urgency=low

  * EA-12082: Update ea-nodejs18 from v18.20.1 to v18.20.2
  * Command injection via args parameter of child_process.spawn without shell option enabled on Windows (CVE-2024-27980) - (HIGH)

 -- Cory McIntire <cory@cpanel.net>  Wed, 10 Apr 2024 00:00:00 -0000

ea-nodejs18 (18.20.1-1) stable; urgency=low

  * EA-12067: Update ea-nodejs18 from v18.20.0 to v18.20.1
  * CVE-2024-27983 - Assertion failed in node::http2::Http2Session::~Http2Session() leads to HTTP/2 server crash- (High)
  * CVE-2024-27982 - HTTP Request Smuggling via Content Length Obfuscation - (Medium)

 -- Cory McIntire <cory@cpanel.net>  Wed, 03 Apr 2024 00:00:00 -0000

ea-nodejs18 (18.20.0-1) stable; urgency=low

  * EA-12049: Update ea-nodejs18 from v18.19.1 to v18.20.0

 -- Cory McIntire <cory@cpanel.net>  Tue, 26 Mar 2024 00:00:00 -0000

ea-nodejs18 (18.19.1-1) stable; urgency=low

  * EA-11974: Update ea-nodejs18 from v18.19.0 to v18.19.1
  * CVE-2024-21892 - Code injection and privilege escalation through Linux capabilities- (High)
  * CVE-2024-22019 - http: Reading unprocessed HTTP request with unbounded chunk extension allows DoS attacks- (High)
  * CVE-2023-46809 - Node.js is vulnerable to the Marvin Attack (timing variant of the Bleichenbacher attack against PKCS#1 v1.5 padding) - (Medium)
  * CVE-2024-22025 - Denial of Service by resource exhaustion in fetch() brotli decoding - (Medium)

 -- Cory McIntire <cory@cpanel.net>  Wed, 14 Feb 2024 00:00:00 -0000

ea-nodejs18 (18.19.0-1) stable; urgency=low

  * EA-11839: Update ea-nodejs18 from v18.18.2 to v18.19.0

 -- Cory McIntire <cory@cpanel.net>  Thu, 30 Nov 2023 00:00:00 -0000

ea-nodejs18 (18.18.2-1) stable; urgency=low

  * EA-11746: Update ea-nodejs18 from v18.18.0 to v18.18.2
  undici - Cookie headers are not cleared in cross-domain redirect in undici-fetch (High) - (CVE-2023-45143)
  nghttp2 - HTTP/2 Rapid Reset (High) - (CVE-2023-44487)
  Permission model improperly protects against path traversal (High) - (CVE-2023-39331)
  Path traversal through path stored in Uint8Array (High) - (CVE-2023-39332)
  Integrity checks according to policies can be circumvented (Medium) - (CVE-2023-38552)
  Code injection via WebAssembly export names (Low) - (CVE-2023-39333)

 -- Cory McIntire <cory@cpanel.net>  Mon, 16 Oct 2023 00:00:00 -0000

ea-nodejs18 (18.18.0-1) stable; urgency=low

  * EA-11697: Update ea-nodejs18 from v18.17.1 to v18.18.0

 -- Travis Holloway <t.holloway@cpanel.net>  Wed, 20 Sep 2023 00:00:00 -0000

ea-nodejs18 (18.17.1-1) stable; urgency=low

  * ZC-11124: Initial build

 -- Julian Brown <julian.brown@cpanel.net>  Mon, 14 Aug 2023 00:00:00 -0000

