Skip to content

Commit e6c7018

Browse files
committed
2025-01-21, Version 22.13.1 'Jod' (LTS)
This is a security release. Notable changes: * CVE-2025-23083: throw on InternalWorker use when permission model is enabled (High) * CVE-2025-23084: fix path traversal in normalize() on Windows (Medium) * CVE-2025-23085: fix HTTP2 mem leak on premature close and ERR_PROTO (Medium) * CVE-2025-22150 - Use of Insufficiently Random Values in undici fetch() (Medium) PR-URL: nodejs-private/node-private#655
1 parent 984f735 commit e6c7018

File tree

3 files changed

+27
-2
lines changed

3 files changed

+27
-2
lines changed

CHANGELOG.md

+2-1
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,8 @@ release.
3838
</tr>
3939
<tr>
4040
<td valign="top">
41-
<b><a href="doc/changelogs/CHANGELOG_V22.md#22.13.0">22.13.0</a></b><br/>
41+
<b><a href="doc/changelogs/CHANGELOG_V22.md#22.13.1">22.13.1</a></b><br/>
42+
<a href="doc/changelogs/CHANGELOG_V22.md#22.13.0">22.13.0</a><br/>
4243
<a href="doc/changelogs/CHANGELOG_V22.md#22.12.0">22.12.0</a><br/>
4344
<a href="doc/changelogs/CHANGELOG_V22.md#22.11.0">22.11.0</a><br/>
4445
<a href="doc/changelogs/CHANGELOG_V22.md#22.10.0">22.10.0</a><br/>

doc/changelogs/CHANGELOG_V22.md

+24
Original file line numberDiff line numberDiff line change
@@ -9,6 +9,7 @@
99
</tr>
1010
<tr>
1111
<td>
12+
<a href="#22.13.1">22.13.1</a><br/>
1213
<a href="#22.13.0">22.13.0</a><br/>
1314
<a href="#22.12.0">22.12.0</a><br/>
1415
<a href="#22.11.0">22.11.0</a><br/>
@@ -55,6 +56,29 @@
5556
* [io.js](CHANGELOG_IOJS.md)
5657
* [Archive](CHANGELOG_ARCHIVE.md)
5758

59+
<a id="22.13.1"></a>
60+
61+
## 2025-01-21, Version 22.13.1 'Jod' (LTS), @RafaelGSS
62+
63+
This is a security release.
64+
65+
### Notable Changes
66+
67+
* CVE-2025-23083 - src,loader,permission: throw on InternalWorker use when permission model is enabled (High)
68+
* CVE-2025-23085 - src: fix HTTP2 mem leak on premature close and ERR\_PROTO (Medium)
69+
* CVE-2025-23084 - path: fix path traversal in normalize() on Windows (Medium)
70+
71+
Dependency update:
72+
73+
* CVE-2025-22150 - Use of Insufficiently Random Values in undici fetch() (Medium)
74+
75+
### Commits
76+
77+
* \[[`520da342e0`](https://github.com/nodejs/node/commit/520da342e0)] - **(CVE-2025-22150)** **deps**: update undici to v6.21.1 (Matteo Collina) [nodejs-private/node-private#662](https://github.com/nodejs-private/node-private/pull/662)
78+
* \[[`99f217369f`](https://github.com/nodejs/node/commit/99f217369f)] - **(CVE-2025-23084)** **path**: fix path traversal in normalize() on Windows (Tobias Nießen) [nodejs-private/node-private#555](https://github.com/nodejs-private/node-private/pull/555)
79+
* \[[`984f735e35`](https://github.com/nodejs/node/commit/984f735e35)] - **(CVE-2025-23085)** **src**: fix HTTP2 mem leak on premature close and ERR\_PROTO (RafaelGSS) [nodejs-private/node-private#650](https://github.com/nodejs-private/node-private/pull/650)
80+
* \[[`2446870618`](https://github.com/nodejs/node/commit/2446870618)] - **(CVE-2025-23083)** **src,loader,permission**: throw on InternalWorker use (RafaelGSS) [nodejs-private/node-private#651](https://github.com/nodejs-private/node-private/pull/651)
81+
5882
<a id="22.13.0"></a>
5983

6084
## 2025-01-07, Version 22.13.0 'Jod' (LTS), @ruyadorno

src/node_version.h

+1-1
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@
2929
#define NODE_VERSION_IS_LTS 1
3030
#define NODE_VERSION_LTS_CODENAME "Jod"
3131

32-
#define NODE_VERSION_IS_RELEASE 0
32+
#define NODE_VERSION_IS_RELEASE 1
3333

3434
#ifndef NODE_STRINGIFY
3535
#define NODE_STRINGIFY(n) NODE_STRINGIFY_HELPER(n)

0 commit comments

Comments
 (0)