Poick

This is a cached version of https://nodejs.org/en/blog/vulnerability/openssl-fixes-in-regular-releases-jun2022 from 2/28/2026, 3:15:21 PM.

Node.js — OpenSSL update assessment, and Node.js project plans

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

Skip to contentCommercial support for versions past the Maintenance LTS phase is available through our OpenJS Ecosystem Sustainability Program partnersOpenSSL update assessment, and Node.js project plansRGRafael GonzagaOpenSSL update assessment, and Node.js project plansSummary The vulnerabilities in the OpenSSL Security releases of Jun 21 2022 do not affect any active Node.js release lines. Analysis Our assessment of the security advisory is: The c_rehash script allows command injection (CVE-2022-2068) Node.js doesn't use or ship the c_rehash script. Therefore, Node.js is not affected Contact and future updates The current Node.js security policy can be found at https://github.com/nodejs/node/security/policy#security, including information on how to report a vulnerability in Node.js. Subscribe to the low-volume announcement-only nodejs-sec mailing list at https://groups.google.com/forum/#!forum/nodejs-sec to stay up to date on security vulnerabilities and security-related releases of Node.js and the projects maintained in the nodejs GitHub organization.PreviousJuly 7th 2022 Security ReleasesNextOpenSSL update assessment, and Node.js project plans