Node.js 25.3.0 is a security release addressing seven CVEs. Key fixes include adding a default TLS error handler, network permission checks for pipe connections, stricter symlink API permissions, disabling futimes in permission model, fixing stack overflow exceptions in async_hooks, removing unsafe buffer zero-fill toggle, and routing TLS callback exceptions through error handlers. The release also updates c-ares to v1.34.6 and undici to v7.18.2.

2m read timeFrom nodejs.org
Post cover image
Table of contents
Notable ChangesCommitsSHASUMS
63 Impressions