Node JS
fromInfoWorld
19 hours agoIs your Node.js project really secure?
Dependency security workflows in JavaScript and Node.js lack actionability, leading to late awareness of risks and ineffective responses.
We also patched two potential denial-of-service vulnerabilities when handling large, malformed inputs. One exploits inefficient string concatenation in header parsing under ASGI ( CVE 2025-14550). Concatenating strings in a loop is known to be slow, and we've done fixes in public where the impact is low. The other one ( CVE 2026-1285) exploits deeply nested entities. December's vulnerability in the XML serializer ( CVE 2025-64460) was about those very two themes.