Node.js 26.5.1 is a dedicated security release addressing 10 CVEs across multiple subsystems. Two high-severity vulnerabilities are patched: an HTTP/2 RST stream issue (CVE-2026-56848) and a permission model flaw allowing radix split node grants (CVE-2026-58043). Five medium-severity fixes cover HTTPS session reuse identity checks, PFX agent key handling, SQLite iterator invalidation, DNS large reply handling, and zlib out-of-bounds writes. Two low-severity permission model issues and one HTTP max header count enforcement fix are also included. Dependencies llhttp (9.4.3) and undici (8.9.0) are updated.
75.9K Impressions