Node.js 22.23.2 (LTS) is a security-only release addressing 10 CVEs across http2, https, permission model, dns, zlib, and http modules. Two high-severity issues affect http2 (memory retention in session accounting and RST stream handling). Three high/medium permission model vulnerabilities are patched. Additional medium fixes cover HTTPS session reuse identity checks, DNS large reply handling, and zlib out-of-bounds writes. Dependencies llhttp (9.4.3) and undici (6.28.0) are also updated.
19.1K Impressions