# Updates on CVE for End-of-Life Versions

DevFeed: [Updates on CVE for End-of-Life Versions](<https://devfeed.tech/articles/updates-on-cve-for-end-of-life-versions-2914.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/vulnerability/updates-cve-for-end-of-life>)

Published: 2025-03-07T16:00:00Z

Content type: news

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Security](<https://devfeed.tech/topics/security.md>), [releases](<https://devfeed.tech/topics/releases.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [end-of-life](<https://devfeed.tech/tags/end-of-life.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [scanners](<https://devfeed.tech/tags/scanners.md>), [security](<https://devfeed.tech/tags/security.md>), [updates](<https://devfeed.tech/tags/updates.md>), [upgrade](<https://devfeed.tech/tags/upgrade.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

## AI overview

The Node.js team updated its CVE policy for end-of-life releases after CVE-2025-23087, CVE-2025-23088, and CVE-2025-23089 were rejected by the CVE Program. New CVEs will include EOL releases unless specific information shows that a vulnerability does not apply. Node.js does not routinely assess EOL versions because of limited resources and their differing dependencies, build processes, and platform support.

## Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.