The most surprising to me is that NodeJS says they are affected https://nodejs.org/en/blog/vulnerability/openssl-november-20...
> Node.js v18.x and v19.x use OpenSSL v3. Therefore these release lines are impacted by this update.
> Node.js 14.x and v16.x are not affected by this OpenSSL update.
> At this stage, due to embargo, the exact nature of these defects is uncertain as well as the impact they will have on Node.js users.
> After assessing the impact on Node.js, it will be decided whether the issues fixed require immediate security releases of Node.js, or whether they can be included in the normally scheduled updates.