Skip to content

A few vulnerabilities in node-cache version 1.26.5 #726

@paosfocalt

Description

@paosfocalt

Hi Team, during our routine security scans, we are seeing a few vulns for the latest tag for node-cache.

CVE-2025-22871 |   | critical | 9.1 | 1.23.8, 1.24.2 |   |   |   |  
CVE-2025-47907 |   | high | 7 | 1.23.12, 1.24.6 |   |   |   |  
CVE-2025-0913 |   | medium | 5.5 | 1.23.10, 1.24.4 |   |   |   |  
CVE-2025-47906 |   | medium | 6.5 | 1.23.12, 1.24.6 |   |   |   |  
CVE-2025-4673 |   | medium | 6.8 | 1.23.10, 1.24.4
CVE-2025-58063
CVE-2025-59530
CVE-2025-4802
CVE-2025-47907 |   | high | 7 | 1.23.12, 1.24.6 |   |   |   |  
CVE-2025-47906 |   | medium | 6.5 | 1.23.12, 1.24.6

Can we have an estimate of when these vulns are expected to be remediated? Thanks.

Metadata

Metadata

Assignees

No one assigned

    Labels

    lifecycle/rottenDenotes an issue or PR that has aged beyond stale and will be auto-closed.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions