CVE-2025-23089

Description

A flaw was found in Node.js. This vulnerability allows potential exposure to unaddressed software vulnerabilities via the continued use of End-of-Life (EOL) versions that no longer receive security updates or patches.

Statement

This CVE has been marked as Rejected by the assigning CNA.

Red Hat Enterprise Linux is not impacted by this CVE, as it does not include or ship any End-of-Life (EOL) versions of Node.js in its supported repositories. Red Hat ensures that all components provided in its distributions are actively maintained and receive necessary updates, including security patches, to mitigate vulnerabilities and maintain system security.

Understanding the Weakness (CWE)

Other

Technical Impact: Reduce Maintainability; Varies by Context

Relying on unmaintained components makes it difficult or impossible to fix significant bugs and vulnerabilities, can render code obsolete, and undermine security by complicating maintenance and increasing the risk of new vulnerabilities.

Frequently Asked Questions

Want to get errata notifications? Sign up here.