|
9 | 9 | </tr> |
10 | 10 | <tr> |
11 | 11 | <td> |
| 12 | +<a href="#18.20.6">18.20.6</a><br/> |
12 | 13 | <a href="#18.20.5">18.20.5</a><br/> |
13 | 14 | <a href="#18.20.4">18.20.4</a><br/> |
14 | 15 | <a href="#18.20.3">18.20.3</a><br/> |
|
75 | 76 | * [io.js](CHANGELOG_IOJS.md) |
76 | 77 | * [Archive](CHANGELOG_ARCHIVE.md) |
77 | 78 |
|
| 79 | +<a id="18.20.6"></a> |
| 80 | + |
| 81 | +## 2025-01-21, Version 18.20.6 'Hydrogen' (LTS), @RafaelGSS |
| 82 | + |
| 83 | +This is a security release. |
| 84 | + |
| 85 | +### Notable Changes |
| 86 | + |
| 87 | +* CVE-2025-23085 - src: fix HTTP2 mem leak on premature close and ERR\_PROTO (Medium) |
| 88 | +* CVE-2025-23084 - path: fix path traversal in normalize() on Windows (Medium) |
| 89 | + |
| 90 | +Dependency update: |
| 91 | + |
| 92 | +* CVE-2025-22150 - Use of Insufficiently Random Values in undici fetch() (Medium) |
| 93 | + |
| 94 | +### Commits |
| 95 | + |
| 96 | +* \[[`c03ad5ed63`](https://github.com/nodejs/node/commit/c03ad5ed63)] - **build**: use rclone instead of aws CLI (Michaël Zasso) [#55617](https://github.com/nodejs/node/pull/55617) |
| 97 | +* \[[`8232463294`](https://github.com/nodejs/node/commit/8232463294)] - **build, tools**: drop leading `/` from `r2dir` (Richard Lau) [#53951](https://github.com/nodejs/node/pull/53951) |
| 98 | +* \[[`b26bcd3394`](https://github.com/nodejs/node/commit/b26bcd3394)] - **build, tools**: copy release assets to staging R2 bucket once built (flakey5) [#51394](https://github.com/nodejs/node/pull/51394) |
| 99 | +* \[[`56df127b7b`](https://github.com/nodejs/node/commit/56df127b7b)] - **build,tools**: simplify upload of shasum signatures (Michaël Zasso) [#53892](https://github.com/nodejs/node/pull/53892) |
| 100 | +* \[[`a63e9372ed`](https://github.com/nodejs/node/commit/a63e9372ed)] - **(CVE-2025-22150)** **deps**: update undici to v5.28.5 (Matteo Collina) [nodejs-private/node-private#657](https://github.com/nodejs-private/node-private/pull/657) |
| 101 | +* \[[`da2d177f91`](https://github.com/nodejs/node/commit/da2d177f91)] - **(CVE-2025-23084)** **path**: fix path traversal in normalize() on Windows (Tobias Nießen) [nodejs-private/node-private#555](https://github.com/nodejs-private/node-private/pull/555) |
| 102 | +* \[[`6cc8d58e6f`](https://github.com/nodejs/node/commit/6cc8d58e6f)] - **(CVE-2025-23085)** **src**: fix HTTP2 mem leak on premature close and ERR\_PROTO (RafaelGSS) [nodejs-private/node-private#650](https://github.com/nodejs-private/node-private/pull/650) |
| 103 | + |
78 | 104 | <a id="18.20.5"></a> |
79 | 105 |
|
80 | 106 | ## 2024-11-12, Version 18.20.5 'Hydrogen' (LTS), @aduh95 |
|
0 commit comments