Stories

  1. node 2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

    This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes…

  2. node 2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

    Node.js 22.23.2 'Jod' is a security release containing several high- and medium-severity fixes. The listed high-severity changes address HTTP/2 header memory accounting, stream resets, and permission handling, alongside HTTPS and DNS fixes.

Publishers