Oracle's October 2020 Security Advisory states that mysql-cluster is vulnerable to CVE-2020-8174: napi_get_value_string_*() allows various kinds of memory corruption in node < 10.21.0, 12.18.0, and < 14.4.0. The advisory lists <7.3.30, <7.4.29, <7.6.15, and <8.0.21 as affected. Please bump.
ping