File tree Expand file tree Collapse file tree
apps/site/pages/en/blog/vulnerability Expand file tree Collapse file tree Original file line number Diff line number Diff line change @@ -6,11 +6,16 @@ layout: blog-post
66author : Rafael Gonzaga
77---
88
9- # Rationale for Issuing CVEs on End-of-Life Node.js Versions
10-
11- ** TL;DR:** CVE-2025 -23087, CVE-2025 -23088, and CVE-2025 -23089 have been
12- rejected by MITRE and therefore the Node.js team decided to update previous
13- CVEs to cover EOL releases, reflecting their ongoing security risks.
9+ # Update on the issuance of CVEs to mark End-of-Life Node.js Versions
10+
11+ ** TL;DR:** CVE-2025 -23087, CVE-2025 -23088, and CVE-2025 -23089 issued to
12+ tag EOL versions have been rejected by MITRE.
13+ The Node.js team has, therefore, decided to update previous vulnerability specific
14+ CVEs to cover EOL releases, reflecting their ongoing security risks. This means that
15+ all new CVEs issued will include EOL releases in the applicability until we have specific
16+ information that indicates a CVE does not apply to an EOL release line. The project
17+ does not plan to evaluate CVEs against EOL lines but information provided to the
18+ project may be used to update the applicability if/when it is available.
1419
1520On January 21, 2025, Node.js released security patches for four active release
1621lines. At the same time, CVEs were assigned to cover EOL (end-of-life) versions:
You can’t perform that action at this time.
0 commit comments