From 7a949e8f8f43527aacd1061bc3cbb19ea1c8fac2 Mon Sep 17 00:00:00 2001 From: Rafael Gonzaga Date: Wed, 14 Jan 2026 21:41:28 -0300 Subject: [PATCH] Blog: change impact for CVE-2025-59464 (#8550) * Blog: change impact for CVE-2025-59464 * Update apps/site/pages/en/blog/vulnerability/december-2025-security-releases.md Co-authored-by: Joyee Cheung Signed-off-by: Rafael Gonzaga --------- Signed-off-by: Rafael Gonzaga Co-authored-by: Joyee Cheung --- .../en/blog/vulnerability/december-2025-security-releases.md | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/apps/site/pages/en/blog/vulnerability/december-2025-security-releases.md b/apps/site/pages/en/blog/vulnerability/december-2025-security-releases.md index 6a36f702473d4..b71bf5608db8a 100644 --- a/apps/site/pages/en/blog/vulnerability/december-2025-security-releases.md +++ b/apps/site/pages/en/blog/vulnerability/december-2025-security-releases.md @@ -103,7 +103,10 @@ TLS connections. Over time this can lead to resource exhaustion and denial of se Impact: -- This vulnerability affects all users in active release lines: 20.x, 22.x, 24.x +- This vulnerability was already fixed on Node.js v24.12.0. It has no impact on + other active release lines. + +This public CVE is only issued for the affected v24 releases. Thank you, to giant_anteater for reporting this vulnerability and thank you RafaelGSS for fixing it.