Node.js Releases Urgent Patches for Multiple Vulnerabilities Exposing Systems to DoS and Crashes
ID: 5749a195-93f6-551a-8c73-878e9b7c1d33
STIX ID: report--5749a195-93f6-551a-8c73-878e9b7c1d33
Feed Name: GBHackers
Node.js issued an urgent LTS security update (v20.20.2 ‘Iron’ and corresponding releases) addressing seven vulnerabilities: a high-severity TLS SNICallback crash (CVE-2026-21637) that can remotely crash processes without authentication, several medium-severity issues including an HTTP/2 memory leak (CVE-2026-21714), a V8 HashDoS vector (CVE-2026-21717), and an HMAC timing oracle (CVE-2026-21713), plus low-severity permission-model bypasses; administrators are advised to upgrade immediately to the patched releases.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
