-
-
Notifications
You must be signed in to change notification settings - Fork 6.5k
Blog: change impact for CVE-2025-59464 #8550
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Conversation
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
👋 Codeowner Review RequestThe following codeowners have been identified for the changed files: Team reviewers: @nodejs/nodejs-website Please review the changes when you have a chance. Thank you! 🙏 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Pull request overview
This PR updates the impact statement for CVE-2025-59464 in the December 2025 security releases blog post. The vulnerability was already fixed in Node.js v24.12.0, and this security release is only issuing the public CVE announcement for it.
Changes:
- Updated the impact description for CVE-2025-59464 to clarify that the vulnerability was already fixed in v24.12.0 and has no impact on other active release lines
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
| - This vulnerability was already fixed on Node.js v24.12.0. It has no impact on | ||
| other active release lines. | ||
|
|
||
| This security release only issued the public CVE for that. |
Copilot
AI
Jan 14, 2026
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Grammatical error: 'issued' should be 'issues' (present tense) to maintain consistency with the document's present tense narrative style, or the sentence should be restructured to 'This security release only issues the public CVE for this vulnerability.'
| This security release only issued the public CVE for that. | |
| This security release only issues the public CVE for this vulnerability. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@RafaelGSS Does this sentence mean to say that "the CVE is only issued for 24, not older releases"?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Yes, correct. Any suggestion?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
| This security release only issued the public CVE for that. | |
| This public CVE is only issued for the affected v24 releases. |
(Based on nodejs/security-wg#1544)
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## main #8550 +/- ##
==========================================
+ Coverage 75.00% 75.01% +0.01%
==========================================
Files 103 103
Lines 9036 9036
Branches 311 311
==========================================
+ Hits 6777 6778 +1
+ Misses 2257 2256 -1
Partials 2 2 ☔ View full report in Codecov by Sentry. |
📦 Build Size ComparisonSummary
Changes➕ Added Assets (1)
➖ Removed Assets (1)
|
No description provided.