€0.00 — free as in speechtonight's forecast: clear skies over production Cache: warm · Deploys: fair, 0% rollbacks expectedset by moonlight, shipped before dawn · deploy freely Page A2

The Daily Commit The Nightly Build

Dev news, typeset daily — PHP · AI · The Wider Stack

The developer's evening paper — PHP · AI · The Wider Stack

Friday, July 31, 2026 Vol. I — No. 214 · Morning editionLate edition EN DE FR ES

Dev · Security

Node.js 22.23.2 security release patches ten CVEs

The Node.js project has published Node.js 22.23.2 (LTS 'Jod'), a security release fixing ten CVEs — three rated high — affecting HTTP/2, the permission model, HTTPS, DNS and zlib.

curated by Sönke

Immediate upgrades are recommended.

The Node.js project has shipped Node.js 22.23.2 (LTS 'Jod') as a security release. The release notes, published July 29, 2026 by Marco Ippolito, detail the fixes.

Ten CVEs are addressed. The three high-severity issues are: CVE-2026-56846, where HTTP/2 header memory was not retained in session accounting; CVE-2026-56848, concerning deferred RST stream handling in HTTP/2 while still in scope; and CVE-2026-58043, a flaw in the permission model that could grant access through radix split nodes.

Four medium-severity fixes cover HTTPS agent key handling for PFX object arrays (CVE-2026-56850), binding identity checks to TLS session reuse (CVE-2026-58040), handling of large resolveAny DNS replies (CVE-2026-58042), and out-of-bounds write buffers in zlib (CVE-2026-58045).

Three low-severity issues were also patched: enforcing filesystem write permission for trace events (CVE-2026-56847), checking the final report output path in the permission model (CVE-2026-58039), and rejecting HTTP requests that exceed the maximum header count (CVE-2026-58044). Key contributors include Matteo Collina and RafaelGSS.

Additionally, the bundled llhttp parser was updated to 9.4.3 and undici to 6.28.0. Binaries and installers for Windows, macOS, Linux and AIX are available from nodejs.org, and users running v22.23.2 should update promptly.

Read the original source ↗

Rate this article: 0

Readers’ Forum

No contributions yet — open the debate.

The Daily CommitThe Nightly Build — Page A1