Stories

  1. node 2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

    Node.js Blog This is a security release. Notable Changes (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes…

  2. node 2026-07-29, Version 26.5.1 (Current), @RafaelGSS

    Node.js BlogNode.js 26.5.1 is a security release with high- and medium-severity fixes, including issues in HTTP/2, permissions, HTTPS, and SQLite. The listed vulnerabilities include CVE-2026-56848 and CVE-2026-58043, both rated High.

  3. node 2026-07-29, Version 22.23.2 'Jod' (LTS), @marco-ippolito

    Node.js BlogNode.js 22.23.2 'Jod' is a security release containing several high- and medium-severity fixes. The listed high-severity changes address HTTP/2 header memory accounting, stream resets, and permission handling, alongside HTTPS and DNS fixes.

Publishers