https://seclists.org/oss-sec/2026/q1/79: NodeJS Security leases (CVE-2025-55131, CVE-2025-55130, CVE-2025-59465, and others)
Published Jan 16, 2026
·Updated
Affected Software
2 affected components
npm/node>=8.0.0
redhat/nodejs>=16.0.0
Frequently Asked Questions
1
What is the severity of CVE-2025-55131?
CVE-2025-55131 is classified as a high-severity vulnerability that can lead to denial of service attacks.
2
How do I fix CVE-2025-55130?
To fix CVE-2025-55130, update to the latest version of Node.js or apply any provided patches.
3
What systems are affected by CVE-2025-59465?
CVE-2025-59465 affects npm and Node.js installations, particularly on Red Hat systems.
4
What is the impact of CVE-2025-55130 on my application?
CVE-2025-55130 can allow attackers to exploit the application, leading to possible crashes or service outages.
5
Are there any mitigation strategies for CVE-2025-59465?
Mitigation strategies for CVE-2025-59465 include updating software dependencies and implementing proper input validation.