2026-06-24, Version 26.4.0 (Current), @aduh95
2026-06-26T08:52:13Z•5ed76ef94b3ba0df6e17f7a6de02b263a31b1cd216ad5efb1618fd713070d338
LTSNUL-bytesSNIcryptocurrentdnshttphttp2macOS-universal-binarymemory-growthnodejssecurity-releasetls
What happened
Node.js published multiple releases (including v26.4.0, v26.3.1, v26.3.0 and LTS releases v24.18.0/v24.17.0 and v22.23.0/v22.23.1). Security releases (notably on 2026-06-18) address several vulnerabilities: two High severity issues (CVE-2026-48618 — TLS hostname normalization for server identity checks; CVE-2026-48933 — WebCrypto cipher output length) and multiple Medium severity fixes (proxy credential redaction in tunnel errors, capping http2 originSet to prevent unbounded memory growth, SNI matching fixes, rejecting hostnames with embedded NUL bytes, TLS session binding to authenticated/… ,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- nodejs_node_releases
- Record identifier
- 5ed76ef94b3ba0df6e17f7a6de02b263a31b1cd216ad5efb1618fd713070d338
- Enrichment time
- 2026-06-26T08:52:13Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.