Node.js
Read post

Node.js — Node.js 24.18.1 (LTS)

Node.js 24.18.1 (LTS, codename 'Krypton') is a security-only release addressing 11 CVEs across multiple subsystems. High-severity fixes include two HTTP/2 vulnerabilities (memory retention in session accounting and deferred RST stream handling) and a permission model bypass via radix split nodes. Medium-severity fixes cover HTTPS session reuse identity checks, PFX agent key disambiguation, SQLite iterator invalidation on statement reset, DNS large reply handling, and zlib out-of-bounds write protection. Low-severity fixes address permission enforcement for trace events, report output path checks, and HTTP max header count enforcement. Dependencies llhttp (9.4.3) and undici (7.29.0) are also updated.

    #security#javascript#nodejs
Jul 29•3m read time•From nodejs.org
Post cover image
98.2K Impressions5 Comments
Node.js's image
Node.js

The Node.js Blog offers developers insights into Node.js runtime, JavaScript ecosystem, and server-s...

850 Followers

•

1.8K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard