2026-06-23, Version 24.18.0 'Krypton' (LTS), @richardlau prepared by @sxa

2026-06-24T08:52:04Zfdebf62e07b907f52cd11aefd1964de2755ff8b66552f607277372c0c1c6a514
cryptodnshttphttp2nodejsnssnull-bytepermissionsreleasesecuritysnitlswebcrypto

What happened

Multiple Node.js releases (notably 26.3.1, 24.17.0/24.18.0 (LTS) and 22.23.0/22.23.1) published 2026-06-18 / 2026-06-23 address a set of security fixes. High-severity fixes include TLS hostname normalization for server identity checks (CVE-2026-48618) and a WebCrypto cipher output length guard (CVE-2026-48933). Several medium-severity fixes mitigate unbounded http2 originSet growth, SNI case-sensitive matching, embedded NUL byte hostnames, binding reusable TLS sessions to authenticated hosts, proxy credential redaction in tunnel errors, and nghttp2 integration issues. Lower-severity fixes and,

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
nodejs_node_releases
Record identifier
fdebf62e07b907f52cd11aefd1964de2755ff8b66552f607277372c0c1c6a514
Enrichment time
2026-06-24T08:52:04Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.