草薙 沙耶(KUSANAGI)@kusanagi_sayaPatch
The KUSANAGI 9 release updates the nodejs module to 22.22.2‑1, addressing multiple CVE‑2026 vulnerabilities and providing a patch for the identified weaknesses.
Aun shah/ Ali memon@Aunshah102Patch
An update patches CVE-2026-21710, CVE-2026-21716, and CVE-2026-21715 by applying null prototype fixes to the http module and adding permission checks to lib/fs/promises and realpath.native.
Aun shah/ Ali memon@Aunshah102Patch
The tweet announces that lower‑severity vulnerabilities CVE‑2026‑21716 and CVE‑2026‑21715, affecting permission checks in lib/fs/promises and realpath.native, have been patched.
CVE@CVEnewDisclosure
The post states a Node.js permission model vulnerability affecting fs.realpathSync.native, but offers no PoC, exploit code, or patch details.
Infoflowcloud@infoflowcloudDisclosure
This brief notice announces the Node.js vulnerability CVE-2026-21715, detailing a permission-check flaw in fs.realpathSync.native(), but does not include a PoC, exploit, patch, or proof of active exploitation.
ティー🌐@TeeThetaPatch
A set of eight CVEs has been addressed by updating the undici library to versions 6.24.1 and 7.24.4.
ダース葱@darthnegiPatch
Node.js v24.14.1 is a security patch release that addresses several CVEs; it includes detailed technical fixes for various vulnerabilities.
ダース葱@darthnegiPatch
Node.js v25.8.2 release includes patches for multiple CVEs with detailed technical fixes.