NodeBB eight-flaw security patch release (4.14.2)
Security Patch Release
Summary
Hide ▲
Show ▼
NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affected range is every version before 4.14.0, so administrators need to move off vulnerable releases now. Public exploit code was published with the disclosure, increasing pressure to upgrade quickly.
Related Happenings
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch Release
H score32
First: 11.05.2026 17:30
Last: 11.05.2026 17:30
Sources 1
About this happening:
Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...
Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)
Security Patch ReleaseAbout this happening: Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...
Node.js security update for CVE-2025-59466 and related flaws
Security Patch Release
H score26
First: 14.01.2026 09:05
Last: 14.01.2026 09:05
Sources 1
About this happening:
Node.js released security updates for a critical async_hooks stack-overflow bug that could trigger DoS in production apps. The fix ships in Node.js 20.20.0, 22.2...
Node.js security update for CVE-2025-59466 and related flaws
Security Patch ReleaseAbout this happening: Node.js released security updates for a critical async_hooks stack-overflow bug that could trigger DoS in production apps. The fix ships in Node.js 20.20.0, 22.2...
Node-forge developers security patch release for CVE-2025-12816
Security Patch Release
H score31
First: 26.11.2025 21:32
Last: 26.11.2025 21:32
Sources 1
About this happening:
The node-forge maintainers released version 1.3.2 to close CVE-2025-12816, reducing the risk of signature-verification bypass in applications that rely on the libr...
Node-forge developers security patch release for CVE-2025-12816
Security Patch ReleaseAbout this happening: The node-forge maintainers released version 1.3.2 to close CVE-2025-12816, reducing the risk of signature-verification bypass in applications that rely on the libr...
Timeline
-
24.07.2026 10:41 2 articles · 11h ago
NodeBB discloses eight high-severity flaws and urges upgrade to 4.14.2
Initial DisclosureAikido Security disclosed eight high-severity flaws in NodeBB after its AI pentest agents found them in a six-hour source-code review, and exploit code was published alongside the disclosure. NodeBB said it had fixed the issues, advised administrators to move to 4.14.2 released July 23, and noted that every version before 4.14.0 is affected.
Show sources
- NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats — thehackernews.com — 24.07.2026 10:41
- NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats — thehackernews.com — 24.07.2026 10:41