OpenSSL update assessment, and Node.js project plans

Rafael Gonzaga


The vulnerabilities in the OpenSSL Security releases of Jun 21 2022 do not affect any active Node.js release lines.


Our assessment of the security advisory is:

The c_rehash script allows command injection (CVE-2022-2068)

Node.js doesn't use or ship the c_rehash script. Therefore, Node.js is not affected

Contact and future updates

The current Node.js security policy can be found at, including information on how to report a vulnerability in Node.js.

