2026-07-29, Version 26.5.1 (Current), @RafaelGSS

Imported from official source

Cybersecurity Classified by Officially

This is a security release.

Notable Changes

  • (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
  • (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
  • (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
  • (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
  • (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
  • (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
  • (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
  • (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
  • (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
  • (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
  • deps: update llhttp to 9.4.3 (Paolo Insogna)
  • deps: update undici to 8.9.0 (Node.js GitHub Bot)

Commits

This is an extract. The publication continues at the source.

Read the original at the source: https://github.com/nodejs/node/releases/tag/v26.5.1

Officially imported this from Node.js’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Node.js — imported from official source
Official source
https://github.com/nodejs/node/releases.atom ATOM
Imported
September 20, 2026 19:51
Versions
1 recorded
Identity
tag:github.com,2008:Repository/27193779/v26.5.1

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.