ON July 29, 2026, Node.js released patches for 11 vulnerabilities, including 3 rated as high severity affecting HTTP/2, TLS, and core modules. No confirmed exploitation has occurred. The issues include a use-after-free in HTTP/2 handling and permission model weaknesses. Medium and low-severity bugs impact TLS and allow for potential denial-of-service attacks. Users are urged to upgrade to versions 22.23.2, 24.18.1, or 26.5.1. All versions mentioned, including older ones, remain vulnerable.
Node.js Patches 11 Vulnerabilities in July 2026 Security Release
CyberSIXT Evidence Panel
Primary Source
nodejs.org
Article by CyberSIXT