# OpenSSL update assessment, and Node.js project plans

DevFeed: [OpenSSL update assessment, and Node.js project plans](<https://devfeed.tech/articles/openssl-update-assessment-and-node-js-project-plans-2906.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/vulnerability/openssl-fixes-in-regular-releases-may2022>)

Published: 2022-05-05T17:00:15Z

Content type: article

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [releases](<https://devfeed.tech/topics/releases.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>)

Tags: [node](<https://devfeed.tech/tags/node.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [release](<https://devfeed.tech/tags/release.md>), [security-vulnerabilities](<https://devfeed.tech/tags/security-vulnerabilities.md>), [update](<https://devfeed.tech/tags/update.md>)

## AI overview

The article assesses the May 3, 2022 OpenSSL security releases and their relevance to Node.js. It states that Node.js does not use or ship the affected script, does not invoke the custom flag, and does not compile with the affected component, while also noting that Node.js 17.x and 18.x are affected by a CVE rated Low. OpenSSL updates are planned for delivery through the regular Node.js release cycle by the end of May.

## Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.