September 8th, 2020
Summary
The Node.js project will release new versions of all supported release lines on or shortly after Tuesday, September 15, 2020. These releases will fix
- One critical severity issue
- One high severity issue
- One medium severity issue
Impact
The 14.x release line of Node.js is vulnerable to one critical severity issue, one high severity issue, and one medium severity issue.
The 12.x release line of Node.js is vulnerable to one high severity issue, and one medium severity issue.
10.x release line of Node.js is vulnerable to one medium severity issue.
Release timing
Releases will be available at, or shortly after, Tuesday, September 15th, 2020.
Contact and future updates
The current Node.js security policy can be found at https://nodejs.org/en/security/. Please follow the process outlined in https://github.com/nodejs/node/blob/master/SECURITY.md if you wish to report a vulnerability in Node.js.
Subscribe to the low-volume announcement-only nodejs-sec mailing list at https://groups.google.com/forum/#!forum/nodejs-sec to stay up to date on security vulnerabilities and security-related releases of Node.js and the projects maintained in the nodejs GitHub organization.