2026-08-03, Version 26.6.0 (Current), @aduh95

2026-08-04T08:51:49Zc2724dea9c91c7b3a94ca268c1d674533c8c9a6649404d0cb0b86f55537f83b1
CVE-2026-56846CVE-2026-56847CVE-2026-56848CVE-2026-56850CVE-2026-58040CVE-2026-58041CVE-2026-58042CVE-2026-58043CVE-2026-58045CurrentDNSHTTP/2HTTPSJavaScript-runtimeLTSNode.jsOpenSSLSQLitepermissionssecurity-releasesoftware-releasevulnerability-managementzlib

What happened

Node.js release feed covering Current and LTS versions 26.6.0, 24.19.0, 26.5.1, 24.18.1, 22.23.2, 26.5.0, and 26.4.0. The July 29, 2026 releases are security updates addressing high-severity HTTP/2 and permission flaws, plus medium-severity issues in HTTPS identity handling, SQLite iterators, DNS response processing, zlib buffer validation, and related components. Users should upgrade affected Node.js branches to the listed patched releases.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
nodejs_node_releases
Record identifier
c2724dea9c91c7b3a94ca268c1d674533c8c9a6649404d0cb0b86f55537f83b1
Enrichment time
2026-08-04T08:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · 2026-08-03, Version 26.6.0 (Current), @aduh95 · Baitaphish