Skip to content

Commit b2bb305

Browse files
vuln: update core index.json (#1545)
Co-authored-by: Create or Update Pull Request Action <create-or-update-pull-request@users.noreply.github.com>
1 parent 4b57620 commit b2bb305

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

vuln/core/index.json

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2137,8 +2137,8 @@
21372137
"cve": [
21382138
"CVE-2025-59464"
21392139
],
2140-
"vulnerable": "20.x || 22.x || 24.x",
2141-
"patched": "^20.20.0 || ^22.22.0 || ^24.13.0",
2140+
"vulnerable": "24.x",
2141+
"patched": "^24.12.0",
21422142
"ref": "https://nodejs.org/en/blog/vulnerability/december-2025-security-releases",
21432143
"description": "Memory leak that enables remote Denial of Service against applications processing TLS client certificates",
21442144
"overview": "A memory leak in Node.js’s OpenSSL integration occurs when converting `X.509` certificate fields to UTF-8 without freeing the allocated buffer. When applications call `socket.getPeerCertificate(true)`, each certificate field leaks memory, allowing remote clients to trigger steady memory growth through repeated TLS connections. Over time this can lead to resource exhaustion and denial of service.",

0 commit comments

Comments
 (0)