Worker permission bypass via InternalWorker leak in diagnostics.
(CVE-2025-23083)
GOAWAY HTTP/2 frames cause memory leak outside heap. (CVE-2025-23085)
- https://bugs.mageia.org/show_bug.cgi?id=33947
- https://nodejs.org/en/blog/vulnerability/january-2025-security-releases
- https://www.openwall.com/lists/oss-security/2025/01/21/5
- https://www.cve.org/CVERecord?id=CVE-2025-23083
- https://www.cve.org/CVERecord?id=CVE-2025-23085
- 9/core/nodejs-22.13.1-2.mga9
Get the latest Linux and open source security news straight to your inbox.