The Node.js project has released important security updates addressing 11 vulnerabilities across its active branches: 22.x, 24.x, and 26.x. The updates are now available as Node.js versions v22.23.2, v24.18.1, and v26.5.1. The July 2026 security release includes fixes for vulnerabilities related to HTTP/2 processing, the Permission Model, HTTPS connection reuse, DNS resolution, SQLite handling, Zlib APIs, and the HTTP parser. Additionally, Node.js has updated its bundled Undici dependency to versions 8.9.0, 7.29.0, and 6.28.0, depending on the release line, along with the llhttp dependency to version 9.4.3. Two high-severity HTTP/2 vulnerabilities could potentially allow remote attackers to disrupt Node.js services. CVE-2026-56846...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!