Node.js released security updates for all active release lines, shipping v22.23.2, v24.18.1, and v26.5.1 to fix 11 vulnerabilities affecting the 22.x, 24.x, and 26.x branches. The most serious issues include two high-severity HTTP/2 flaws, CVE-2026-56846 and CVE-2026-56848, which could let attackers trigger denial of service through memory exhaustion or process crashes, and CVE-2026-58043, a high-severity bypass in the Permission Model that could allow applications started with --permission to access filesystem paths outside the intended allowlist.
The update also addresses weaknesses involving HTTPS connection reuse, mTLS identity reuse, hostname verification bypass, DNS handling, SQLite, zlib APIs, and an HTTP parser issue that could enable request smuggling in Node.js-based forwarding proxies. An oss-sec follow-up noted that an earlier announcement linked to the wrong Node.js blog entry and should instead reference the July security releases page, while maintainers emphasized that unsupported Node.js versions remain exposed and should be retired or upgraded immediately.

See real exploitation activity before you spend the cycle.
2 events from the most recent confirmed update back to the earliest known activity.
Node.js released July 2026 security updates for its active 22.x, 24.x, and 26.x release lines. The patched versions are v22.23.2, v24.18.1, and v26.5.1, addressing 11 vulnerabilities including high-severity flaws affecting HTTP/2 handling and the Permission Model.
An oss-sec mailing list follow-up noted that a link in the Node.js security update announcement was likely incorrect and should point to the July 2026 security releases page instead of the June 2026 page. The correction was raised by Alan Coopersmith in response to Rafael Gonzaga's announcement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourceseclists.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.