2026-07-29, Version 26.5.1 (Current), @RafaelGSS

2026-07-31T08:51:49Zcdb396e52cfe233861bab1b1dbd02813775eefd71f5e37f9b648b69eb0a68767
CVE-2026-48615CVE-2026-48618CVE-2026-48619CVE-2026-48933CVE-2026-56846CVE-2026-56847CVE-2026-56848CVE-2026-56850CVE-2026-58039CVE-2026-58040CVE-2026-58041CVE-2026-58042CVE-2026-58043CVE-2026-58044CVE-2026-58045DNSHTTPHTTP/2HTTPSLTSNode.jsSQLiteTLSWebCryptodenial-of-servicememory-safetypatch-updatepermission-modelpotential-authentication-bypasssecurity-releasezlib

What happened

Node.js published security releases for Current v26.5.1 and LTS v24.18.1/v22.23.2 on 2026-07-29. Fixes address high-severity HTTP/2 memory/resource handling, permission-model bypasses, HTTPS identity and key handling, SQLite iterator invalidation, DNS response processing, zlib buffer bounds, and HTTP header-count handling. The feed also includes an earlier v26.3.1 security release fixing TLS hostname validation and WebCrypto output-length issues. Organizations should upgrade supported Node.js branches to the listed patched versions.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
nodejs_node_releases
Record identifier
cdb396e52cfe233861bab1b1dbd02813775eefd71f5e37f9b648b69eb0a68767
Enrichment time
2026-07-31T08:51:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · 2026-07-29, Version 26.5.1 (Current), @RafaelGSS · Baitaphish