CVE-2025-55131: Node.js Node
High severity, CVSS 7.1. EPSS: 3.5% chance of exploitation in the next 30 days.
A flaw in Node.js's buffer allocation logic can expose uninitialized memory when allocations are interrupted, when using the `vm` module with the timeout option. Under specific timing conditions, buffers allocated with `Buffer.alloc` and other `TypedArray` instances like `Uint8Array` may contain leftover data from previous operations, allowing in-process secrets like tokens or passwords to leak or causing data corruption. While exploitation typically requires precise timing or in-process code execution, it can become remotely exploitable when untrusted input influences workload and timeouts, leading to potential confidentiality and integrity impact.
Affected products
- Node.js Node: from 20, up to and including 20.19.6; from 22, up to and including 22.21.1; from 24, up to and including 24.12.0; from 25, up to and including 25.2.1; from 4.0, before 5 (fixed in 5); from 5.0, before 6 (fixed in 6); …
- Red Hat Red Hat Enterprise Linux 10: before 1:24.13.0-1.el10_1 (fixed in 1:24.13.0-1.el10_1); before 1:22.22.0-3.el10_1 (fixed in 1:22.22.0-3.el10_1)
- Red Hat Red Hat Enterprise Linux 10.0 Extended Update Support: before 1:22.22.0-1.el10_0 (fixed in 1:22.22.0-1.el10_0)
- Red Hat Red Hat Enterprise Linux 8: before 8100020260116121421.6d880403 (fixed in 8100020260116121421.6d880403); before 8100020260119091831.6d880403 (fixed in 8100020260119091831.6d880403); before 8100020260119100525.489197e6 (fixed in 8100020260119100525.489197e6)
- Red Hat Red Hat Enterprise Linux 9: before 9070020260117213814.rhel9 (fixed in 9070020260117213814.rhel9); before 9070020260117213838.rhel9 (fixed in 9070020260117213838.rhel9); before 9070020260117213748.rhel9 (fixed in 9070020260117213748.rhel9)
- Red Hat Red Hat Enterprise Linux 9.4 Extended Update Support: before 9040020260211171433.rhel9 (fixed in 9040020260211171433.rhel9)
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 9060020260210180816.rhel9 (fixed in 9060020260210180816.rhel9); before 9060020260210120402.rhel9 (fixed in 9060020260210120402.rhel9)
- Red Hat Red Hat Hardened Images: before 24.14.1-4.hum1 (fixed in 24.14.1-4.hum1); before 25.9.0-1.hum1 (fixed in 25.9.0-1.hum1); before 20.20.0-7.1.hum1 (fixed in 20.20.0-7.1.hum1); before 22.22.0-1.3.hum1 (fixed in 22.22.0-1.3.hum1)
Published 2026-01-20. Last modified 2026-07-15.