2026-06-24, Version 26.4.0 (Current), @aduh95
2026-06-25T08:52:08Z•d1baf5151aaf2f7d2e95f3557f82016d9179041dcbb89f3f18cd1cd497c4f1b7
cryptocvednshttphttp2memory-leaknodejspermissionsrelease-notessecuritysnitlswebcrypto
What happened
June 2026 Node.js release notes: a feature release (v26.4.0 on 2026-06-24) and multiple security releases (notably v26.3.1 / v24.17.0 / v22.23.0 on 2026-06-18). The security updates address multiple vulnerabilities across TLS, WebCrypto/crypto, http/http2, DNS/net, and the permission model — including two High severity issues (TLS hostname normalization and WebCrypto cipher output length) and several Medium/Low issues (unbounded originSet memory growth, SNI matching, embedded NUL hostnames, session binding, response queue poisoning, proxy credential redaction, permission model fixes, and ngtcp
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- nodejs_node_releases
- Record identifier
- d1baf5151aaf2f7d2e95f3557f82016d9179041dcbb89f3f18cd1cd497c4f1b7
- Enrichment time
- 2026-06-25T08:52:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.