The Node.js project has shipped Node.js 22.23.2 (LTS 'Jod') as a security release. The release notes, published July 29, 2026 by Marco Ippolito, detail the fixes.
Ten CVEs are addressed. The three high-severity issues are: CVE-2026-56846, where HTTP/2 header memory was not retained in session accounting; CVE-2026-56848, concerning deferred RST stream handling in HTTP/2 while still in scope; and CVE-2026-58043, a flaw in the permission model that could grant access through radix split nodes.
Four medium-severity fixes cover HTTPS agent key handling for PFX object arrays (CVE-2026-56850), binding identity checks to TLS session reuse (CVE-2026-58040), handling of large resolveAny DNS replies (CVE-2026-58042), and out-of-bounds write buffers in zlib (CVE-2026-58045).
Three low-severity issues were also patched: enforcing filesystem write permission for trace events (CVE-2026-56847), checking the final report output path in the permission model (CVE-2026-58039), and rejecting HTTP requests that exceed the maximum header count (CVE-2026-58044). Key contributors include Matteo Collina and RafaelGSS.
Additionally, the bundled llhttp parser was updated to 9.4.3 and undici to 6.28.0. Binaries and installers for Windows, macOS, Linux and AIX are available from nodejs.org, and users running v22.23.2 should update promptly.
Comments
No comments yet — be the first.
Open the discussion
No account or password needed — just enter your e-mail and we’ll send you a one-time sign-in link. First time here? You’re set up automatically.
Your rating will be applied automatically after you sign in.
Check your inbox
We’ve sent a sign-in link to …. Open it on this device — this tab will sign you in automatically.
Waiting for your click …
·