logo

Node.js Patches Multiple Vulnerabilities That Enable DoS Attacks and Process Crashes

ID: d30cc55e-fc49-50bd-b64f-b8dfbbe83b44

STIX ID: report--d30cc55e-fc49-50bd-b64f-b8dfbbe83b44

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-03-25

Date Updated: 2026-04-21

Author: Guru Baran

...
...

Node.js published a security release (LTS) addressing seven CVEs affecting TLS (critical SNICallback flaw allowing unauthenticated process crashes), HTTP/2 flow-control (memory leak/DoS), V8 string-hashing (HashDoS), Web Crypto HMAC timing oracle, HTTP header prototype pollution, and two permission-model filesystem bypasses; administrators should urgently upgrade affected 20.x/22.x/24.x/25.x releases to the provided patched versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.