Node.js Ships 22.23.2, 24.18.1, and 26.5.1 Emergency Security Patch Fixing 10 CVEs Across All Active Releases

Published by

Node.js has released emergency security patches for versions 22.23.2, 24.18.1, and 26.5.1 to address 10 CVEs, including three high-severity vulnerabilities related to HTTP/2 routing and memory management. The updates, delayed by two days due to infrastructure issues, also fix medium-severity flaws involving DNS response handling and zlib compression. Developers are urged to update their active release lines immediately and review the July 2026 security advisory before restarting services. The patches were mainly developed by community contributors and highlight the project's commitment to security



Node.js Ships 22.23.2, 24.18.1, and 26.5.1 Emergency Security Patch Fixing 10 CVEs Across All Active Releases

Node.js has published coordinated security patches for 22.23.2, 24.18.1, and 26.5.1 after a two-day delay caused by infrastructure issues. The release addresses 10 CVEs, including three high-severity vulnerabilities that exploit HTTP/2 routing, heap memory management, and the --permission sandbox model. Medium-severity fixes round out the update by patching DNS response handling, zlib compression crashes, and mTLS certificate reuse flaws. Developers should update their active release lines immediately and review the full July 2026 security advisory before restarting services.

Node.js Ships 22.23.2, 24.18.1, and 26.5.1 Emergency Security Patch Fixing 10 CVEs Across All Active Releases @ Linux Compatible