Node released version 22.23.1 (LTS)
This patch fixes an unexpected behavior from the previous security release.
See the latest news and media coverage for Node. We track all announcements, press releases, and industry mentions in real time, all in one place.
Cross-platform JavaScript runtime environment
nodejs.orgLast updated
In short: Node released major version 26, implemented a yearly LTS-focused release schedule, and addressed critical security vulnerabilities across all lines.
This patch fixes an unexpected behavior from the previous security release.
It addresses multiple CVEs in TLS, crypto, HTTP2, and other components, including critical and medium severity vulnerabilities.
The highest severity issue is HIGH, affecting 26.x, 24.x, and 22.x release lines.
Includes updates to buffer, crypto, and http, plus potential changes to macOS binary availability.
Six Proto6 flaws in protobuf.js enable RCE and DoS attacks; patched in versions 7.5.6 and 8.0.2 to protect Node.js services.
Discover the new features of Node.js 26, including the Temporal API enabled by default, enhancing date and time handling for developers.
Attackers can once again break out of the Node.js sandbox vm2 and execute malicious code on the host system. Security updates provide a remedy.
No flags, no polyfills, no workarounds. The release also upgrades V8 to version 14.6, ships Undici 8, and removes several legacy APIs that have been...
Track Node and your other target companies to get real-time alerts and weekly summaries delivered straight to your inbox.
Browse news for competitors to Node and other trending companies.