2026-06-23, Version 24.18.0 'Krypton' (LTS), @richardlau prepared by @sxa
2026-06-24T08:52:04Z•fdebf62e07b907f52cd11aefd1964de2755ff8b66552f607277372c0c1c6a514
cryptodnshttphttp2nodejsnssnull-bytepermissionsreleasesecuritysnitlswebcrypto
What happened
Multiple Node.js releases (notably 26.3.1, 24.17.0/24.18.0 (LTS) and 22.23.0/22.23.1) published 2026-06-18 / 2026-06-23 address a set of security fixes. High-severity fixes include TLS hostname normalization for server identity checks (CVE-2026-48618) and a WebCrypto cipher output length guard (CVE-2026-48933). Several medium-severity fixes mitigate unbounded http2 originSet growth, SNI case-sensitive matching, embedded NUL byte hostnames, binding reusable TLS sessions to authenticated hosts, proxy credential redaction in tunnel errors, and nghttp2 integration issues. Lower-severity fixes and,
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- nodejs_node_releases
- Record identifier
- fdebf62e07b907f52cd11aefd1964de2755ff8b66552f607277372c0c1c6a514
- Enrichment time
- 2026-06-24T08:52:04Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.