logo

Node.js Issues Security Updates: High-Severity DoS and Permission Bypasses Patched

ID: 764af57b-50c9-54b7-a505-8c0793e48988

STIX ID: report--764af57b-50c9-54b7-a505-8c0793e48988

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-03-25

Date Updated: 2026-04-23

Author: Ddos

...
...

Node.js released critical security updates addressing nine CVEs across 20.x, 22.x, 24.x, and 25.x. The most severe are two high-risk flaws that can cause immediate process crashes (CVE-2026-21637 and CVE-2026-21710) and several permission-model bypasses permitting unauthorized network or filesystem actions; other fixes include HMAC timing, HTTP/2 memory leak, and V8 HashDoS issues. Administrators should upgrade to v20.20.2, v22.22.2, v24.14.1, or v25.8.2 immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.