oss-sec mailing list archives

Re: NodeJS Security Releases (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465, and others)


From: Jan Schaumann <jschauma () netmeister org>
Date: Tue, 13 Jan 2026 20:44:06 -0500

Alan Coopersmith <alan.coopersmith () oracle com> wrote:

The node.js team has also published a much more in-depth discussion at:
https://nodejs.org/en/blog/vulnerability/january-2026-dos-mitigation-async-hooks

Thanks for that - this link would have been useful for
the NodeJS team to share on their nodejs-sec mailing
list.

with a shorter intro in the thread starting at:
https://x.com/matteocollina/status/2011137343323865196

Here's a link that doesn't require an account on, uhm,
_that_ platform:

https://nitter.net/matteocollina/status/2011137343323865196#m

-Jan


Current thread: