Node.js Security Release Patches 7 Vulnerabilities Across All Release Lines
ID: 8ecb38ce-1501-5301-b471-4ab30a2cd361
STIX ID: report--8ecb38ce-1501-5301-b471-4ab30a2cd361
Feed Name: cybersecurityNews.com
Threat Score
Node.js published critical security updates (20.20.0, 22.22.0, 24.13.0, 25.3.0) addressing multiple high- and medium-severity CVEs — notably a Buffer.alloc race exposing prior memory (CVE-2025-55131), a symlink-based filesystem permission bypass (CVE-2025-55130), and an HTTP/2 malformed frame DoS (CVE-2025-59465) — and urges immediate upgrades for production HTTP/2 servers and permission-enabled environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
