Find notable cyber news and cases, enriched with sources, timelines, and signals.

NodeBB eight-flaw security patch release (4.14.2)

Security Patch Release
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

NodeBB released 4.14.2 to close eight high-severity flaws that exposed admin access, private messages, private categories, and code-execution paths. The affected range is every version before 4.14.0, so administrators need to move off vulnerable releases now. Public exploit code was published with the disclosure, increasing pressure to upgrade quickly.

Related Happenings

Linux kernel Dirty Frag patch release (CVE-2026-43284, CVE-2026-43500)

Security Patch Release
H score32 First: 11.05.2026 17:30 Last: 11.05.2026 17:30 Sources 1

About this happening: Major Linux distributions are rolling out fixes for Dirty Frag, the Linux kernel patch release that covers CVE-2026-43284 and CVE-2026-43500. The update matter...

Node.js security update for CVE-2025-59466 and related flaws

Security Patch Release
H score26 First: 14.01.2026 09:05 Last: 14.01.2026 09:05 Sources 1

About this happening: Node.js released security updates for a critical async_hooks stack-overflow bug that could trigger DoS in production apps. The fix ships in Node.js 20.20.0, 22.2...

Node-forge developers security patch release for CVE-2025-12816

Security Patch Release
H score31 First: 26.11.2025 21:32 Last: 26.11.2025 21:32 Sources 1

About this happening: The node-forge maintainers released version 1.3.2 to close CVE-2025-12816, reducing the risk of signature-verification bypass in applications that rely on the libr...

Timeline

  1. 24.07.2026 10:41 2 articles · 11h ago

    NodeBB discloses eight high-severity flaws and urges upgrade to 4.14.2

    Initial Disclosure

    Aikido Security disclosed eight high-severity flaws in NodeBB after its AI pentest agents found them in a six-hour source-code review, and exploit code was published alongside the disclosure. NodeBB said it had fixed the issues, advised administrators to move to 4.14.2 released July 23, and noted that every version before 4.14.0 is affected.

    Show sources