A request smuggling vulnerability was found in Node.js that can be exploited under certain unspecified circumstances. External Reference: https://nodejs.org/en/blog/vulnerability/february-2016-security-releases/
Created nodejs tracking bugs for this issue: Affects: fedora-all [bug 1306207] Affects: epel-all [bug 1306208]
nodejs-0.10.42-4.fc23 has been pushed to the Fedora 23 stable repository. If problems still persist, please make note of it in this bug report.
nodejs-0.10.42-4.fc22 has been pushed to the Fedora 22 stable repository. If problems still persist, please make note of it in this bug report.
nodejs-0.10.42-4.el6 has been pushed to the Fedora EPEL 6 stable repository. If problems still persist, please make note of it in this bug report.
nodejs-0.10.42-4.el7 has been pushed to the Fedora EPEL 7 stable repository. If problems still persist, please make note of it in this bug report.
Openshift uses latest RHSCL nodejs-4-rhel7 image which include NodeJS 4.6.2. Marking Openshift Enterprise as not affected. https://github.com/openshift/library/blob/master/official/nodejs/imagestreams/nodejs-rhel7.json#L64
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2016-2086