OpenSSL November Security Release

Summary The Node.js project may be releasing new versions across all of its supported release lines in the first week of November to incorporate upstream patches from OpenSSL. Please read on for full details. OpenSSL The OpenSSL project announced will release OpenSSL 3.0.7 on the 1th of November 2022 between Read more…

September 22nd 2022 Security Releases

Summary The Node.js project will release new versions of the 14.x, 16.x, and 18.x releases lines on or shortly after Thursday, September 22nd, 2022 in order to address: Three medium severity issues. One high severity issues. Impact The 18.x release line of Node.js is vulnerable to four medium severity issues Read more…

July 5th 2022 Security Releases

Summary The Node.js project will release new versions of the 14.x, 16.x, and 18.x releases lines on or shortly after Tuesday, July 5th, 2022 in order to address: Three medium severity issues. Two high severity issues. Impact The 18.x release line of Node.js is vulnerable to three medium severity issues Read more…

OpenSSL update assessment, and Node.js project plans

Summary The OpenSSL Security releases of May 3 2022 affects Node.js 17.x and 18.x but highest serverity is “Low” Analysis Our assessment of the security advisory is: The 1c_rehash script allows command injection (CVE-2022-1292) Node.js doesn’t use or ship the 1c_rehash script. Therefore, Node.js is not affected 1OCSP_basic_verify may incorrectly Read more…

January 10th 2022 Security Releases

Summary The Node.js project will release new versions of the 12.x, 14.x, 16.x, and 17.x releases lines on or shortly after Monday, January 10th, 2021 in order to address: Three medium severity issues One low severity issue Impact The 17.x release line of Node.js is vulnerable to three medium severity Read more…

October 12th 2021 Security Releases

Summary The Node.js project will release new versions of the 12.x, 14.x, and 16.x releases lines on or shortly after Tuesday October 12th, 2021 in order to address: Two medium severity issues Impact The 16.x release line of Node.js is vulnerable to two medium severity issues. The 14.x release line Read more…

August 31 2021 Security Releases

Summary The Node.js project will release new versions of 12.x, and 14.x releases lines on or shortly after Tuesday August 31th, 2021 in order to address: Three high severity issues, and two moderate severity issues. Impact The 14.x release line of Node.js is vulnerable to three high severity issues, and Read more…