oss-sec mailing list archives
Re: NodeJS Security Releases (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465, and others)
From: Jan Schaumann <jschauma () netmeister org>
Date: Tue, 13 Jan 2026 20:44:06 -0500
Alan Coopersmith <alan.coopersmith () oracle com> wrote:
The node.js team has also published a much more in-depth discussion at: https://nodejs.org/en/blog/vulnerability/january-2026-dos-mitigation-async-hooks
Thanks for that - this link would have been useful for the NodeJS team to share on their nodejs-sec mailing list.
with a shorter intro in the thread starting at: https://x.com/matteocollina/status/2011137343323865196
Here's a link that doesn't require an account on, uhm, _that_ platform: https://nitter.net/matteocollina/status/2011137343323865196#m -Jan
Current thread:
- NodeJS Security Releases (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465, and others) Jan Schaumann (Jan 13)
- Re: NodeJS Security Releases (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465, and others) Alan Coopersmith (Jan 13)
- Re: NodeJS Security Releases (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465, and others) Jan Schaumann (Jan 13)
- Re: NodeJS Security Releases (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465, and others) Michel Lind (Jan 16)
- Re: NodeJS Security Releases (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465, and others) Jan Schaumann (Jan 16)
- Re: NodeJS Security Releases (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465, and others) Jan Schaumann (Jan 13)
- Re: NodeJS Security Releases (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465, and others) Alan Coopersmith (Jan 13)
