Change History (5)
comment:1 by , 9 months ago
comment:2 by , 9 months ago
| Priority: | normal → high |
|---|
Security Fixes
- CVE-2025-55130 (High): Bypass File System Permissions using crafted symlinks
- CVE-2025-55131 (High): Timeout-based race conditions make Uint8Array/Buffer.alloc non-zerofilled
- CVE-2025-55132 (Low): fs.futimes() Bypasses Read-Only Permission Model
- CVE-2025-59465 (High): Node.js HTTP/2 server crashes with unhandled error when receiving malformed HEADERS frame
- CVE-2025-59466 (Medium): Uncatchable "Maximum call stack size exceeded" error on Node.js via async_hooks leads to process crashes bypassing error handlers
- CVE-2026-21637 (Medium): Node.js permission model bypass via unchecked Unix Domain Socket connections (UDS)
Information was obtained from https://nodejs.org/en/blog/vulnerability/december-2025-security-releases.
Other fixes
- deps: update c-ares to v1.34.6
- deps: update undici to 6.23.0
Note:
See TracTickets
for help on using tickets.

This is a security release. I'll adjust this pretty soon here.