node: January 21, 2025 Security Releases
authorHirokazu MORIKAWA <[email protected]>
Thu, 23 Jan 2025 08:05:17 +0000 (17:05 +0900)
committerTianling Shen <[email protected]>
Fri, 24 Jan 2025 07:53:20 +0000 (15:53 +0800)
commit4a0f436644658369122022a804316339df26d71e
treedc0d1f48f9d12822b485448f0780e516007eb57e
parent211fbad7012d03c9e4bc77ed541944b4e1bc45ba
node: January 21, 2025 Security Releases

Notable Changes

    CVE-2025-23085 - src: fix HTTP2 mem leak on premature close and ERR_PROTO (Medium)
    CVE-2025-23084 - path: fix path traversal in normalize() on Windows (Medium)

Dependency update:

    CVE-2025-22150 - Use of Insufficiently Random Values in undici fetch() (Medium)

Signed-off-by: Hirokazu MORIKAWA <[email protected]>
lang/node/Makefile