logo

Node.js Security Release Patches 7 Vulnerabilities Across All Release Lines

ID: 8ecb38ce-1501-5301-b471-4ab30a2cd361

STIX ID: report--8ecb38ce-1501-5301-b471-4ab30a2cd361

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-01-13

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Node.js published critical security updates (20.20.0, 22.22.0, 24.13.0, 25.3.0) addressing multiple high- and medium-severity CVEs — notably a Buffer.alloc race exposing prior memory (CVE-2025-55131), a symlink-based filesystem permission bypass (CVE-2025-55130), and an HTTP/2 malformed frame DoS (CVE-2025-59465) — and urges immediate upgrades for production HTTP/2 servers and permission-enabled environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.