Node releases Node.js 22.23.0 (LTS) with security fixes
It addresses multiple CVEs in TLS, crypto, HTTP2, and other components, including critical and medium severity vulnerabilities.
See the latest news and media coverage for Node. We track all announcements, press releases, and industry mentions in real time, all in one place.
Cross-platform JavaScript runtime environment
nodejs.orgLast updated
In short: Node released version 26.0 with the Temporal API enabled by default and announced a new annual release cycle for improved volunteer sustainability.
It addresses multiple CVEs in TLS, crypto, HTTP2, and other components, including critical and medium severity vulnerabilities.
The highest severity issue is HIGH, affecting 26.x, 24.x, and 22.x release lines.
Includes updates to buffer, crypto, and http, plus potential changes to macOS binary availability.
The update includes new features like randomUUIDv7, debugger probes, and various improvements.
Six Proto6 flaws in protobuf.js enable RCE and DoS attacks; patched in versions 7.5.6 and 8.0.2 to protect Node.js services.
Discover the new features of Node.js 26, including the Temporal API enabled by default, enhancing date and time handling for developers.
Attackers can once again break out of the Node.js sandbox vm2 and execute malicious code on the host system. Security updates provide a remedy.
No flags, no polyfills, no workarounds. The release also upgrades V8 to version 14.6, ships Undici 8, and removes several legacy APIs that have been...
Track Node and your other target companies to get real-time alerts and weekly summaries delivered straight to your inbox.
Browse news for competitors to Node and other trending companies.