https://seclists.org/oss-sec/2026/q1/379: NodeJS Security leases fixes High, 5 Medium, 2 Low severity issues
Published Mar 25, 2026
·Updated
Affected Software
3 affected components
Node.js Node.js<20.20.2, <22.22.2, <24.14.1, <25.8.2
npm/undici<6.24.1, <7.24.4
V8 V8
Frequently Asked Questions
1
What is the severity of the Node.js vulnerability reported on March 25, 2026?
The Node.js vulnerability includes high severity, five medium severity, and two low severity issues.
2
How do I fix the Node.js vulnerabilities from March 25, 2026?
To fix the vulnerabilities, update to the latest versions of the Node.js release lines 25.x, 24.x, 22.x, and 20.x.
3
What versions of Node.js are affected by the March 25, 2026 vulnerabilities?
The vulnerabilities affect Node.js versions 20.x, 22.x, 24.x, and 25.x.
4
Can I continue using my application with the Node.js vulnerabilities from March 25, 2026?
It is not recommended to continue using applications with known vulnerabilities without applying the necessary updates.
5
Where can I find the details about the Node.js vulnerabilities published on March 25, 2026?
Details about the Node.js vulnerabilities can be found in the security advisory published by the Node.js team.