From 1977e892cae525a951860394f902c398e86bb910 Mon Sep 17 00:00:00 2001 From: Marco Ippolito Date: Mon, 8 Dec 2025 17:58:38 +0100 Subject: [PATCH 1/2] chore: annouce december security release --- .../december-2025-security-releases.md | 39 +++++++++++++++++++ apps/site/site.json | 8 ++-- 2 files changed, 43 insertions(+), 4 deletions(-) create mode 100644 apps/site/pages/en/blog/vulnerability/december-2025-security-releases.md diff --git a/apps/site/pages/en/blog/vulnerability/december-2025-security-releases.md b/apps/site/pages/en/blog/vulnerability/december-2025-security-releases.md new file mode 100644 index 0000000000000..a176d09788bd0 --- /dev/null +++ b/apps/site/pages/en/blog/vulnerability/december-2025-security-releases.md @@ -0,0 +1,39 @@ +--- +date: 2025-12-08T23:00:00.000Z +category: vulnerability +title: Monday, December 15, 2025 Security Releases +slug: december-2025-security-releases +layout: blog-post +author: The Node.js Project +--- + +# Summary + +The Node.js project will release new versions of the 25.x, 24.x, 22.x, 20.x +releases lines on or shortly after, Monday, December 15, 2025 in order to address: + +- 3 high severity issues. +- 1 low severity issues. +- 1 medium severity issues. + +## Impact + +The 25.x release line of Node.js is vulnerable to 3 high severity issues, 1 low severity issues. +The 24.x release line of Node.js is vulnerable to 3 high severity issues, 1 low severity issues, 1 medium severity issues. +The 22.x release line of Node.js is vulnerable to 3 high severity issues, 1 low severity issues, 1 medium severity issues. +The 20.x release line of Node.js is vulnerable to 3 high severity issues, 1 low severity issues, 1 medium severity issues. + +It's important to note that End-of-Life versions are always affected when a security release occurs. +To ensure your system's security, please use an up-to-date version as outlined in our +[Release Schedule](https://github.com/nodejs/release#release-schedule). + +## Release timing + +Releases will be available on, or shortly after, Monday, December 15, 2025. + +## Contact and future updates + +The current Node.js security policy can be found at . +Please follow the process outlined in if you wish to report a vulnerability in Node.js. + +Subscribe to the low-volume announcement-only nodejs-sec mailing list at to stay up to date on security vulnerabilities and security-related releases of Node.js and the projects maintained in the nodejs GitHub organization. diff --git a/apps/site/site.json b/apps/site/site.json index 22381906522cf..97ec51f6f4400 100644 --- a/apps/site/site.json +++ b/apps/site/site.json @@ -28,10 +28,10 @@ ], "websiteBanners": { "index": { - "startDate": "2025-07-15T00:00:00.000Z", - "endDate": "2025-07-22T00:00:00.000Z", - "text": "July Security Release is available", - "link": "https://nodejs.org/en/blog/vulnerability/july-2025-security-releases", + "startDate": "2025-12-08T23:00:00.000Z", + "endDate": "2025-12-15T23:00:00.000Z", + "text": "New security releases to be made available Monday, December 15, 2025", + "link": "https://nodejs.org/en/blog/vulnerability/december-2025-security-releases", "type": "warning" } }, From b5b16cab21c570bb1e2320d98ece5e4bfce38914 Mon Sep 17 00:00:00 2001 From: Marco Ippolito Date: Mon, 8 Dec 2025 18:04:30 +0100 Subject: [PATCH 2/2] fixup Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com> Signed-off-by: Marco Ippolito --- .../vulnerability/december-2025-security-releases.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/apps/site/pages/en/blog/vulnerability/december-2025-security-releases.md b/apps/site/pages/en/blog/vulnerability/december-2025-security-releases.md index a176d09788bd0..cad20c421ec96 100644 --- a/apps/site/pages/en/blog/vulnerability/december-2025-security-releases.md +++ b/apps/site/pages/en/blog/vulnerability/december-2025-security-releases.md @@ -13,15 +13,15 @@ The Node.js project will release new versions of the 25.x, 24.x, 22.x, 20.x releases lines on or shortly after, Monday, December 15, 2025 in order to address: - 3 high severity issues. -- 1 low severity issues. -- 1 medium severity issues. +- 1 low severity issue. +- 1 medium severity issue. ## Impact -The 25.x release line of Node.js is vulnerable to 3 high severity issues, 1 low severity issues. -The 24.x release line of Node.js is vulnerable to 3 high severity issues, 1 low severity issues, 1 medium severity issues. -The 22.x release line of Node.js is vulnerable to 3 high severity issues, 1 low severity issues, 1 medium severity issues. -The 20.x release line of Node.js is vulnerable to 3 high severity issues, 1 low severity issues, 1 medium severity issues. +The 25.x release line of Node.js is vulnerable to 3 high severity issues, 1 low severity issue. +The 24.x release line of Node.js is vulnerable to 3 high severity issues, 1 low severity issue, 1 medium severity issue. +The 22.x release line of Node.js is vulnerable to 3 high severity issues, 1 low severity issue, 1 medium severity issue. +The 20.x release line of Node.js is vulnerable to 3 high severity issues, 1 low severity issue, 1 medium severity issue. It's important to note that End-of-Life versions are always affected when a security release occurs. To ensure your system's security, please use an up-to-date version as outlined in our