2026-07-29, Version 26.5.1 (Current), @RafaelGSS
Cybersecurity Classified by Officially
This is a security release.
Notable Changes
- (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
- (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
- (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
- (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
- (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
- (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
- (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
- (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
- (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
- (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
- deps: update llhttp to 9.4.3 (Paolo Insogna)
- deps: update undici to 8.9.0 (Node.js GitHub Bot)
Commits
This is an extract. The publication continues at the source.
Read the original at the source: https://github.com/nodejs/node/releases/tag/v26.5.1
Officially imported this from Node.js’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
Provenance
- Organization
- Node.js — imported from official source
- Official source
- https://github.com/nodejs/node/releases.atom ATOM
- Imported
- September 20, 2026 19:51
- Versions
- 1 recorded
- Identity
tag:github.com,2008:Repository/27193779/v26.5.1