Node.js 26.5.1 is a dedicated security release addressing 10 CVEs across multiple subsystems. Two high-severity vulnerabilities are patched: an HTTP/2 RST stream issue (CVE-2026-56848) and a permission model flaw allowing radix split node grants (CVE-2026-58043). Five medium-severity fixes cover HTTPS session reuse identity checks, PFX agent key handling, SQLite iterator invalidation, DNS large reply handling, and zlib out-of-bounds writes. Two low-severity permission model issues and one HTTP max header count enforcement fix are also included. Dependencies llhttp (9.4.3) and undici (8.9.0) are updated.

3m read timeFrom nodejs.org
Post cover image
76K Impressions