| Name | Modified | Size | Downloads / Week |
|---|---|---|---|
| Parent folder | |||
| 2026-07-29, Version 24.18.1 _Krypton_ (LTS), @juanarbol source code.tar.gz | 2026-07-29 | 127.6 MB | |
| 2026-07-29, Version 24.18.1 _Krypton_ (LTS), @juanarbol source code.zip | 2026-07-29 | 153.9 MB | |
| README.md | 2026-07-29 | 5.0 kB | |
| Totals: 3 Items | 281.5 MB | 4 | |
This is a security release.
Notable Changes
- (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High
- (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
- (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
- (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
- (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
- (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
- (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
- (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
- (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
- (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
- (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
- deps: update llhttp to 9.4.3 (Paolo Insogna)
- deps: update undici to 7.29.0 (Node.js GitHub Bot)
Commits
- [
6cb0475751] - deps: update llhttp to 9.4.3 (Paolo Insogna) [nodejs-private/node-private#935](https://github.com/nodejs-private/node-private/issues/935) - [
bcfe21d3dc] - deps: update undici to 7.29.0 (Node.js GitHub Bot) #64713 - [
9d0d36cffd] - (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) [nodejs-private/node-private#929](https://github.com/nodejs-private/node-private/issues/929) - [
8a008fb523] - (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) [nodejs-private/node-private#922](https://github.com/nodejs-private/node-private/issues/922) - [
a77c7f7354] - (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) [nodejs-private/node-private#921](https://github.com/nodejs-private/node-private/issues/921) - [
34ed88a069] - (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) #63752 - [
95ba2cfde7] - (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) [nodejs-private/node-private#904](https://github.com/nodejs-private/node-private/issues/904) - [
fcbdbe47ea] - (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) [nodejs-private/node-private#930](https://github.com/nodejs-private/node-private/issues/930) - [
ea26c12b56] - (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) [nodejs-private/node-private#911](https://github.com/nodejs-private/node-private/issues/911) - [
9a6b7e343a] - (CVE-2026-58039) permission: check final report output path (RafaelGSS) [nodejs-private/node-private#926](https://github.com/nodejs-private/node-private/issues/926) - [
6c0c990880] - (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) [nodejs-private/node-private#927](https://github.com/nodejs-private/node-private/issues/927) - [
af9ff0490c] - (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) [nodejs-private/node-private#896](https://github.com/nodejs-private/node-private/issues/896) - [
05f541b5c0] - (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) [nodejs-private/node-private#931](https://github.com/nodejs-private/node-private/issues/931)