RHSA-2025:1351
Advisory lineage Upstream: 3 Downstream: 0
Published: 13 Feb 2025, 10:05
Last modified:12 Jul 2026, 10:03
Vulnerability Summary
Overall Risk (default)
medium
31/100 CVSS Score
7.7 HIGH
3.0 (osv_red_hat)
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
13 Feb 2025, 10:05
Published
Vulnerability first disclosed
12 Jul 2026, 10:03
Last Modified
Vulnerability information updated
Description
Red Hat Security Advisory: nodejs:20 security update
CVSS Metrics
- v3.0•HIGH•Score: 7.7CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Systems
- redhat•nodejs
< 1:20.18.2-1.module+el8.10.0+22767+a3309b10
- redhat•nodejs-debuginfo
< 1:20.18.2-1.module+el8.10.0+22767+a3309b10
- redhat•nodejs-debugsource
< 1:20.18.2-1.module+el8.10.0+22767+a3309b10
- redhat•nodejs-devel
< 1:20.18.2-1.module+el8.10.0+22767+a3309b10
- redhat•nodejs-docs
< 1:20.18.2-1.module+el8.10.0+22767+a3309b10
- redhat•nodejs-full-i18n
< 1:20.18.2-1.module+el8.10.0+22767+a3309b10
- redhat•nodejs-nodemon
< 0:3.0.1-1.module+el8.10.0+22767+a3309b10
- redhat•nodejs-packaging
< 0:2021.06-4.module+el8.10.0+22767+a3309b10
- redhat•nodejs-packaging-bundler
< 0:2021.06-4.module+el8.10.0+22767+a3309b10
- redhat•npm
< 1:10.8.2-1.20.18.2.1.module+el8.10.0+22767+a3309b10
References (24)
- https://access.redhat.com/errata/RHSA-2025:1351
- https://access.redhat.com/security/updates/classification/#important
- https://bugzilla.redhat.com/show_bug.cgi?id=2339176
- https://bugzilla.redhat.com/show_bug.cgi?id=2339392
- https://bugzilla.redhat.com/show_bug.cgi?id=2342618
- https://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_1351.json
- https://access.redhat.com/security/cve/CVE-2025-22150
- https://www.cve.org/CVERecord?id=CVE-2025-22150
- https://nvd.nist.gov/vuln/detail/CVE-2025-22150
- https://blog.securityevaluators.com/hacking-the-javascript-lottery-80cc437e3b7f
- https://github.com/nodejs/undici/blob/8b06b8250907d92fead664b3368f1d2aa27c1f35/lib/web/fetch/body.js#L113
- https://github.com/nodejs/undici/commit/711e20772764c29f6622ddc937c63b6eefdf07d0
- https://github.com/nodejs/undici/commit/c2d78cd19fe4f4c621424491e26ce299e65e934a
- https://github.com/nodejs/undici/commit/c3acc6050b781b827d80c86cbbab34f14458d385
- https://github.com/nodejs/undici/security/advisories/GHSA-c76h-2ccp-4975
- https://hackerone.com/reports/2913312
- https://access.redhat.com/security/cve/CVE-2025-23083
- https://www.cve.org/CVERecord?id=CVE-2025-23083
- https://nvd.nist.gov/vuln/detail/CVE-2025-23083
- https://nodejs.org/en/blog/vulnerability/january-2025-security-releases
- https://access.redhat.com/security/cve/CVE-2025-23085
- https://www.cve.org/CVERecord?id=CVE-2025-23085
- https://nvd.nist.gov/vuln/detail/CVE-2025-23085
- https://nodejs.org/pt/blog/vulnerability/january-2025-security-releases