<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 06:24:15 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:1351 — Important: nodejs:20 security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:1351</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: nodejs-packaging-bundler, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* undici: Undici Uses Insufficiently Random Values (CVE-2025-22150)
  * nodejs: Node.js Worker Thread Exposure via Diagnostics Channel (CVE-2025-23083)
  * nodejs: GOAWAY HTTP/2 frames cause memory leak outside heap (CVE-2025-23085)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: nodejs, AlmaLinux:8: nodejs-devel, AlmaLinux:8: nodejs-docs, AlmaLinux:8: nodejs-full-i18n, AlmaLinux:8: nodejs-nodemon, AlmaLinux:8: nodejs-packaging, AlmaLinux:8: nodejs-packaging-bundler, AlmaLinux:8: npm&lt;/p&gt;
&lt;p&gt;Node.js is a software development platform for building fast and scalable network applications in the JavaScript programming language.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* undici: Undici Uses Insufficiently Random Values (CVE-2025-22150)
  * nodejs: Node.js Worker Thread Exposure via Diagnostics Channel (CVE-2025-23083)
  * nodejs: GOAWAY HTTP/2 frames cause memory leak outside heap (CVE-2025-23085)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:1351</guid>
    </item>
    <item>
      <title>bdu:2025-03339</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-03339</link>
      <description>bdu:2025-03339</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-03339</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-23083</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-23083</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: nodejs, BellSoft Hardened Containers:stream: nodejs&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:stream: nodejs, BellSoft Hardened Containers:stream: nodejs&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-23083</guid>
    </item>
    <item>
      <title>BIT-node-2025-23083</title>
      <link>https://cve.radiocsirt.org/vuln/bit-node-2025-23083</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: node&lt;/p&gt;
&lt;p&gt;With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. &#13;
&#13;
This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: node&lt;/p&gt;
&lt;p&gt;With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. &#13;
&#13;
This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-node-2025-23083</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0060 — De multiples vulnérabilités ont été découvertes dans Node.js. Elles permettent à un attaquant de provoquer un déni de s…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0060</link>
      <description>certfr-2025-avi-0060</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0060</guid>
    </item>
    <item>
      <title>EUVD-2026-273299</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-273299</link>
      <description>EUVD-2026-273299</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-273299</guid>
    </item>
    <item>
      <title>fkie_cve-2025-23083</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-23083</link>
      <description>&lt;p&gt;With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. &#13;
&#13;
This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. &#13;
&#13;
This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-23083</guid>
    </item>
    <item>
      <title>GHSA-wv7p-rjf3-9fr5</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wv7p-rjf3-9fr5</link>
      <description>&lt;p&gt;With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage.&lt;/p&gt;
&lt;p&gt;This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage.&lt;/p&gt;
&lt;p&gt;This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wv7p-rjf3-9fr5</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-23083 — With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-23083</link>
      <description>msrc_CVE-2025-23083</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-23083</guid>
    </item>
    <item>
      <title>OESA-2025-1234 — nodejs security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1234</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: nodejs&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;amp;amp;apos;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. &#13;
&#13;
This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.(CVE-2025-23083)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: nodejs&lt;/p&gt;
&lt;p&gt;Node.js is a platform built on Chrome&amp;amp;amp;apos;s JavaScript runtime for easily building fast, scalable network applications. Node.js uses an event-driven, non-blocking I/O model that makes it lightweight and efficient, perfect for data-intensive real-time applications that run across distributed devices.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. &#13;
&#13;
This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.(CVE-2025-23083)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1234</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:14706-1 — corepack22-22.13.0-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:14706-1</link>
      <description>&lt;p&gt;corepack22-22.13.0-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;corepack22-22.13.0-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:14706-1</guid>
    </item>
    <item>
      <title>RHSA-2025:1522 — Red Hat Security Advisory: nodejs:20 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:1522</link>
      <description>&lt;p&gt;nodejs: Node.js Worker Thread Exposure via Diagnostics Channel&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;nodejs: Node.js Worker Thread Exposure via Diagnostics Channel&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:1522</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:0232-1 — Security update for nodejs20</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:0232-1</link>
      <description>&lt;p&gt;Security update for nodejs20&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for nodejs20&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:0232-1</guid>
    </item>
    <item>
      <title>Withdrawn: UBUNTU-CVE-2025-23083</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-23083</link>
      <description>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.04: nodejs&lt;/p&gt;
&lt;p&gt;With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Withdrawn by the publisher.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:25.04: nodejs&lt;/p&gt;
&lt;p&gt;With the aid of the diagnostics_channel utility, an event can be hooked into whenever a worker thread is created. This is not limited only to workers but also exposes internal workers, where an instance of them can be fetched, and its constructor can be grabbed and reinstated for malicious usage. This vulnerability affects Permission Model users (--permission) on Node.js v20, v22, and v23.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-23083</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-0156 — Node.js: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0156</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Node.js ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen preiszugeben, einen Denial-of-Service-Zustand herbeizuführen oder nicht näher spezifizierte Angriffe zu starten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in Node.js ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen preiszugeben, einen Denial-of-Service-Zustand herbeizuführen oder nicht näher spezifizierte Angriffe zu starten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-0156</guid>
    </item>
  </channel>
</rss>
