Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Node.js Security Release Patches 7 Vulnerabilities Across All Release Lines

Node.js Security Release Patches 7 Vulnerabilities Across All Release Lines

Posted on January 13, 2026January 13, 2026 By CWS

Node.js issued important safety updates throughout its energetic launch traces on January 13, 2026, patching vulnerabilities that would result in reminiscence leaks, denial-of-service assaults, and permission bypasses.

These releases handle three high-severity flaws, amongst others, urging speedy upgrades for affected programs.

Excessive Severity Vulnerabilities

Excessive-severity points dominate this launch, with CVE-2025-55131 exposing uninitialized reminiscence in Buffer.alloc and Uint8Array attributable to timeout races within the vm module, probably leaking secrets and techniques like tokens.

CVE-2025-55130 permits symlink assaults to evade filesystem permission flags resembling –allow-fs-read, enabling arbitrary file entry. CVE-2025-59465 crashes HTTP/2 servers by way of malformed HEADERS frames, triggering unhandled TLSSocket errors for distant DoS.​

CVE IDSeverityDescription SummaryAffected VersionsReporter/FixerCVE-2025-55131HighBuffer alloc race exposes prior data20.x,22.x,24.x,25.xNikita Skovoroda/RafaelGSSCVE-2025-55130HighSymlink bypasses FS permissions20.x,22.x,24.x,25.xnatann/RafaelGSSCVE-2025-59465HighHTTP/2 malformed body causes server crash20.x,22.x,24.x,25.xdantt/RafaelGSS

Medium Severity Points

4 medium vulnerabilities embody CVE-2025-59466, the place async_hooks make stack overflow errors uncatchable, bypassing handlers for DoS. CVE-2025-59464 leaks reminiscence in TLS shopper certificates processing by way of OpenSSL UTF-8 conversions.

CVE-2026-21636 bypasses community permissions by way of Unix Area Sockets within the experimental mannequin on v25. CVE-2026-21637 lets TLS PSK/ALPN callbacks throw exceptions that crash servers or leak FDs.

CVE IDSeverityDescription SummaryAffected VersionsReporter/FixerCVE-2025-59466MediumUncatchable stack errors by way of async_hooks20.x,22.x,24.x,25.xAndrewMacPherson/mcollinaCVE-2025-59464MediumTLS cert reminiscence leak20.x,22.x,24.xgiant_anteater/RafaelGSSCVE-2026-21636MediumUDS bypasses web permissions25.xmufeedvh/RafaelGSSCVE-2026-21637MediumTLS callback exceptions trigger DoS/FD leakAll with PSK/ALPN0xmaxhax/mcollina

Low Severity Repair

CVE-2025-55132 permits fs.futimes() to switch timestamps with out write permissions, undermining read-only isolation in permission fashions from v20 to v25.​

Updates embody c-ares 1.34.6 and undici (6.23.0 or 7.18.0) to handle public vulnerabilities. New variations embody Node.js 20.20.0, 22.22.0, 24.13.0, and 25.3.0, accessible by way of normal channels.

Node.js urges customers to prioritize upgrades, particularly for manufacturing HTTP/2 servers and permission-enabled environments, as end-of-life branches stay uncovered.

The Node.js group credit a number of researchers for disclosures, emphasizing group collaboration in securing the ecosystem. A number of postponements ensured thorough testing earlier than at the moment’s rollout.​

Comply with us on Google Information, LinkedIn, and X for each day cybersecurity updates. Contact us to function your tales.

Cyber Security News Tags:Lines, Node.js, Patches, Release, Security, Vulnerabilities

Post navigation

Previous Post: Long-Running Web Skimming Campaign Steals Credit Cards From Online Checkout Pages
Next Post: FortiSandbox SSRF Vulnerability Allow Attacker to proxy Internal Traffic via Crafted HTTP Requests

Related Posts

Google Reports 90 Zero-Day Exploits in 2025 Google Reports 90 Zero-Day Exploits in 2025 Cyber Security News
Critical OpenSSH Vulnerability Exposes Moxa Ethernet Switches to Remote Code Execution Critical OpenSSH Vulnerability Exposes Moxa Ethernet Switches to Remote Code Execution Cyber Security News
CISA Warns of Citrix NetScaler ADC and Gateway Vulnerability Actively Exploited in Attacks CISA Warns of Citrix NetScaler ADC and Gateway Vulnerability Actively Exploited in Attacks Cyber Security News
Critical SAP S/4HANA Vulnerability Actively Exploited to Fully Compromise Your SAP System Critical SAP S/4HANA Vulnerability Actively Exploited to Fully Compromise Your SAP System Cyber Security News
Auditing Data Access Controls for Privacy Regulation Adherence Auditing Data Access Controls for Privacy Regulation Adherence Cyber Security News
10 Best Enterprise Remote Access Software 10 Best Enterprise Remote Access Software Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • FBI Verifies Email Breach as US Offers Reward for Hackers
  • Critical F5 BIG-IP Vulnerability Now Actively Exploited
  • China-Linked Cyber Threats Target Southeast Asian Government
  • AI-Powered VoidLink Malware Framework Poses New Cyber Threat
  • Top Log Monitoring Tools to Watch in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark