Groups
Conversations
All groups and messages
Send feedback to Google
Help
Sign in
Groups
nodejs-sec
Conversations
About
nodejs-sec
1–30 of 50
Mark all as read
Report abusive group
0 selected
Matteo Collina
Jun 28
Node.js security updates for all active release lines, July 2022
The Node.js project will release new versions of all supported release lines on or shortly after
unread,
Node.js security updates for all active release lines, July 2022
The Node.js project will release new versions of all supported release lines on or shortly after
Jun 28
midawson
Jun 21
OpenSSL June 21 release - assessment
Please see the following blog post for the Node.js project's assessment of the recent OpenSSL
unread,
OpenSSL June 21 release - assessment
Please see the following blog post for the Node.js project's assessment of the recent OpenSSL
Jun 21
midawson
May 5
OpenSSL update assessment, and Node.js project plans
Please see the following blog post for the Node.js project's assessment of the recent OpenSSL
unread,
OpenSSL update assessment, and Node.js project plans
Please see the following blog post for the Node.js project's assessment of the recent OpenSSL
May 5
Joe Sepi
2
Mar 17
Node.js security updates for all active release lines, March 2022
The Node.js project has now released new versions of all supported release lines. For more
unread,
Node.js security updates for all active release lines, March 2022
The Node.js project has now released new versions of all supported release lines. For more
Mar 17
Bryan English
2
Jan 10
Node.js security updates for all active release lines, January 2022
The Node.js project has now released new versions of all supported release lines. For more
unread,
Node.js security updates for all active release lines, January 2022
The Node.js project has now released new versions of all supported release lines. For more
Jan 10
midawson
2
12/16/21
Node.js team assessment of OpenSSL Security Advisory for OpenSSL 3.0.1 (CVE-2021-4044).
The link for the CVE was incorrect in the original post. Here is an updated version: ----------------
unread,
Node.js team assessment of OpenSSL Security Advisory for OpenSSL 3.0.1 (CVE-2021-4044).
The link for the CVE was incorrect in the original post. Here is an updated version: ----------------
12/16/21
midawson
2
11/2/21
Node.js project review of CVE-2021-42574 and CVE-2021-42694
For those who asked for more details about the script referenced, it is now also available in GitHub
unread,
Node.js project review of CVE-2021-42574 and CVE-2021-42694
For those who asked for more details about the script referenced, it is now also available in GitHub
11/2/21
Matteo Collina
2
10/12/21
Node.js security updates for all active release lines, October 2021
The Node.js project has now released new versions of all supported release lines. For more
unread,
Node.js security updates for all active release lines, October 2021
The Node.js project has now released new versions of all supported release lines. For more
10/12/21
Daniel Bevenius
2
8/31/21
Node.js security updates for versions 12.x, and 14.x releases lines, August 31 2021
The Node.js project has now released new versions of v14, and v12 release lines. For more information
unread,
Node.js security updates for versions 12.x, and 14.x releases lines, August 31 2021
The Node.js project has now released new versions of v14, and v12 release lines. For more information
8/31/21
midawson
2
8/11/21
Node.js security updates for all active release lines, August 2021
The Node.js project has now released new versions of all supported release lines. For more
unread,
Node.js security updates for all active release lines, August 2021
The Node.js project has now released new versions of all supported release lines. For more
8/11/21
Daniel Bevenius
7/30/21
Security updates for all active release lines, 30 July 2021
Updates are now available for v16.x, v14.x, and v12.x Node.js release lines. We normally like to give
unread,
Security updates for all active release lines, 30 July 2021
Updates are now available for v16.x, v14.x, and v12.x Node.js release lines. We normally like to give
7/30/21
Daniel Bevenius
3
7/1/21
Security updates for all active release lines, July 2021
Sorry, I made a mistake with the url and the correct one is (the same as is the first message in this
unread,
Security updates for all active release lines, July 2021
Sorry, I made a mistake with the url and the correct one is (the same as is the first message in this
7/1/21
Daniel Bevenius
4/30/21
CVE-2020-1604 information
Based on internal discussions, we believe that Node.js is not affected by CVE-2020-16040. This
unread,
CVE-2020-1604 information
Based on internal discussions, we believe that Node.js is not affected by CVE-2020-16040. This
4/30/21
Daniel Bevenius
3
4/7/21
Security updates for all active release lines, April 2021
There was a mistake in the previous post with regards to the following download link for Node v15. It
unread,
Security updates for all active release lines, April 2021
There was a mistake in the previous post with regards to the following download link for Node v15. It
4/7/21
Daniel Bevenius
2
2/23/21
Security updates for all active release lines, February 2021
## _(Update 23-Feb-2021)_ Security releases available Updates are now available for v10.x, v12.x, v14
unread,
Security updates for all active release lines, February 2021
## _(Update 23-Feb-2021)_ Security releases available Updates are now available for v10.x, v12.x, v14
2/23/21
midawson
2/10/21
Node.js team assessment of CVE-2021-21148
Based on internal discussion and consultation with the V8 team, we believe that Node.js is NOT
unread,
Node.js team assessment of CVE-2021-21148
Based on internal discussion and consultation with the V8 team, we believe that Node.js is NOT
2/10/21
midawson
2
1/4/21
Security updates for all active release lines, January 2021
## _(Update 4-Jan-2021)_ Security releases available Updates are now available for v10,x, v12.x, v14.
unread,
Security updates for all active release lines, January 2021
## _(Update 4-Jan-2021)_ Security releases available Updates are now available for v10,x, v12.x, v14.
1/4/21
midawson
2
11/16/20
Security releases for 15.x, 14.x and 12.x release lines
## _(Update 16-Nov-2020)_ Security releases available Updates are now available for v12.x, v14.x and
unread,
Security releases for 15.x, 14.x and 12.x release lines
## _(Update 16-Nov-2020)_ Security releases available Updates are now available for v12.x, v14.x and
11/16/20
Michael Dawson
2
9/15/20
Security updates for all active release lines, September 2020
Updates are now available for v10,x, v12.x and v14.x Node.js release lines for the following issues.
unread,
Security updates for all active release lines, September 2020
Updates are now available for v10,x, v12.x and v14.x Node.js release lines for the following issues.
9/15/20
Sam Roberts
2
6/2/20
Security updates to all supported release lines on or shortly after Tuesday, June 2nd, 2020
Updates are now available for all supported Node.js release lines for the following issues. ### TLS
unread,
Security updates to all supported release lines on or shortly after Tuesday, June 2nd, 2020
Updates are now available for all supported Node.js release lines for the following issues. ### TLS
6/2/20
Sam Roberts
2
2/6/20
Security updates for all active release lines, February 2020
## _(Update 6-February-2020)_ Security releases available Updates are now available for all active
unread,
Security updates for all active release lines, February 2020
## _(Update 6-February-2020)_ Security releases available Updates are now available for all active
2/6/20
Michael Dawson
,
Sam Roberts
3
12/17/19
Security updates for all active release lines, December 2019
## Update 18-December-2019: Releases available These releases update npm to v6.13.4 to address three
unread,
Security updates for all active release lines, December 2019
## Update 18-December-2019: Releases available These releases update npm to v6.13.4 to address three
12/17/19
Sam Roberts
2
9/12/19
OpenSSL releases may require Node.js security releases
### Summary The OpenSSL Security releases of September 10th, 2019 do not affect Node.js. ### Analysis
unread,
OpenSSL releases may require Node.js security releases
### Summary The OpenSSL Security releases of September 10th, 2019 do not affect Node.js. ### Analysis
9/12/19
Sam Roberts
3
8/16/19
Security updates for all active release lines, August 2019
Node.js, as well as many other implementations of HTTP/2, have been found vulnerable to Denial of
unread,
Security updates for all active release lines, August 2019
Node.js, as well as many other implementations of HTTP/2, have been found vulnerable to Denial of
8/16/19
Rod Vagg
2
2/28/19
Security updates for all active release lines, February 2019
Updates are now available for all active Node.js release lines. In addition to fixes for security
unread,
Security updates for all active release lines, February 2019
Updates are now available for all active Node.js release lines. In addition to fixes for security
2/28/19
Rod Vagg
2
11/27/18
Security updates for all active release lines, November 2018
Summary Updates are now available for all active Node.js release lines. These include fixes for the
unread,
Security updates for all active release lines, November 2018
Summary Updates are now available for all active Node.js release lines. These include fixes for the
11/27/18
Rod Vagg
2
8/15/18
Security updates for all active release lines, August 2018
Security releases available Summary Updates are now available for all active Node.js release lines.
unread,
Security updates for all active release lines, August 2018
Security releases available Summary Updates are now available for all active Node.js release lines.
8/15/18
Michael Dawson
2
6/12/18
Security updates for all active release lines, June 2018
Summary Updates are now available for all active Node.js release lines. These include the fix for the
unread,
Security updates for all active release lines, June 2018
Summary Updates are now available for all active Node.js release lines. These include the fix for the
6/12/18
Rod Vagg
2
3/28/18
March 2018 Node.js Security Releases
March 2018 Node.js security releases are now available. See below for full disclosure of the
unread,
March 2018 Node.js Security Releases
March 2018 Node.js security releases are now available. See below for full disclosure of the
3/28/18
Michael Dawson
1/9/18
Meltdown and Spectre - Impact On Node.js
Summary Project zero has recently announced some new attacks that have received a lot of attention:
unread,
Meltdown and Spectre - Impact On Node.js
Summary Project zero has recently announced some new attacks that have received a lot of attention:
1/9/18