Node releases version 24.18.1 (LTS)
This security release patches 11 vulnerabilities, including high-severity issues in http2 and permission modules.
See the latest news and media coverage for Node. We track all announcements, press releases, and industry mentions in real time, all in one place.
Cross-platform JavaScript runtime environment
nodejs.orgLast updated
In short: Node released version 26.0.0 with the Temporal API, overhauled its security releases, and announced a new annual major release schedule.
This security release patches 11 vulnerabilities, including high-severity issues in http2 and permission modules.
Fixes 10 CVEs including high-severity vulnerabilities in http2 and permission.
Addresses multiple high and medium severity vulnerabilities in http2, https, permission, dns, and zlib modules.
The releases address high-severity vulnerabilities across multiple version lines.
Node.js security release July 2026 will patch HIGH severity vulnerabilities across all three active runtime versions — 22.x, 24.x, and 26.x — with patches expected...
Six Proto6 flaws in protobuf.js enable RCE and DoS attacks; patched in versions 7.5.6 and 8.0.2 to protect Node.js services.
Discover the new features of Node.js 26, including the Temporal API enabled by default, enhancing date and time handling for developers.
Attackers can once again break out of the Node.js sandbox vm2 and execute malicious code on the host system. Security updates provide a remedy.
Track Node and your other target companies to get real-time alerts and weekly summaries delivered straight to your inbox.
Browse news for competitors to Node and other trending companies.