Node.js Fixes Critical Flaws, Patches DoS Risk in Latest Security Update
ID: eda2d9cc-447d-5249-8e24-e6cb401170d4
STIX ID: report--eda2d9cc-447d-5249-8e24-e6cb401170d4
Feed Name: The Cyber Express
Node.js released security updates for versions 20.x, 22.x, 24.x, and 25.x addressing multiple CVEs: a high-profile incomplete fix (CVE-2026-21637) that leaves SNICallback exception handling vulnerable to remote DoS, a high-severity HTTP handling bug (CVE-2026-21710) leading to uncaught TypeErrors via crafted headers, several medium issues (permission-model bypass for UDS, assertion crash in url.format, HMAC timing side-channels, HTTP/2 memory leak, V8 HashDoS) and two low-severity permission-related flaws; patched releases were published (v20.20.2, v22.22.2, v24.14.1, v25.8.2).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
