2026-07-29, Version 26.5.1 (Current), @RafaelGSS

Node.js Version 1 original current

Imported from official source

This is a security release. Notable Changes (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low deps: update llhttp to 9.4.3 (Paolo Insogna) deps: update undici to 8.9.0 (Node.js GitHub Bot) Commits [af0bf96877] - deps: update llhttp to 9.4.3 (Paolo Insogna) nodejs-private/node-private#935 [0354678355] - deps: update undici to 8.9.0 (Node.js GitHub Bot) #64712 [dbeeaeec13] - (CVE-2026-580...

This version

Version
1 of 1
Recorded
September 20, 2026 19:51
Change
Initial
Content hash
d6743c255555f7a14ccf62f7aec3bb6e
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.