2026-08-03, Version 26.6.0 (Current), @aduh95
2026-08-04T08:51:49Z•c2724dea9c91c7b3a94ca268c1d674533c8c9a6649404d0cb0b86f55537f83b1
CVE-2026-56846CVE-2026-56847CVE-2026-56848CVE-2026-56850CVE-2026-58040CVE-2026-58041CVE-2026-58042CVE-2026-58043CVE-2026-58045CurrentDNSHTTP/2HTTPSJavaScript-runtimeLTSNode.jsOpenSSLSQLitepermissionssecurity-releasesoftware-releasevulnerability-managementzlib
What happened
Node.js release feed covering Current and LTS versions 26.6.0, 24.19.0, 26.5.1, 24.18.1, 22.23.2, 26.5.0, and 26.4.0. The July 29, 2026 releases are security updates addressing high-severity HTTP/2 and permission flaws, plus medium-severity issues in HTTPS identity handling, SQLite iterators, DNS response processing, zlib buffer validation, and related components. Users should upgrade affected Node.js branches to the listed patched releases.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- nodejs_node_releases
- Record identifier
- c2724dea9c91c7b3a94ca268c1d674533c8c9a6649404d0cb0b86f55537f83b1
- Enrichment time
- 2026-08-04T08:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.