Skip to content

http: add writeInformation to send arbitrary 1xx status codes - #63155

Merged
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
pimterry:h1-additional-headers
May 15, 2026
Merged

http: add writeInformation to send arbitrary 1xx status codes#63155
nodejs-github-bot merged 1 commit into
nodejs:mainfrom
pimterry:h1-additional-headers

Conversation

@pimterry

Copy link
Copy Markdown
Member

This provides a generic HTTP/1 API for 1xx responses, equivalent to our existing HTTP/2 additionalHeaders API. This supports any 1xx status code, except 101, which I've intentionally excluded - since it changes the protocol entirely, there's no possible way to unilaterally send that without breaking things later in our current API, so you just have to use 'upgrade' in that case.

This fixes various past requests like:

And acts as a nice workaround to solve:

(All 3 closed as stale, not fixed)

I'm also hoping it'll discourage usage of the private res._writeRaw method as a workaround for the existing limitations. We even did this in our own tests, see test/parallel/test-http-information-headers.js here.

This is useful to support custom 1xx values (perfectly valid AFAICT, if unusual), proxies (who want to pass through data in a standard way, without having to separately handle each case individually as today) and to give us trivial general support for future standardized 1xx values, without needing a whole separate PR to add a new per-status API every time.

The existing methods are refactored to use the generic method under the hood, and HTTP/2 compat uses additionalHeaders.

There's one annoying inconsistency here: the H1 methods throw if we've already sent a final status code, while the H2 methods just no-op. I've kept that as-is and matched this in the new method to avoid a breaking change, but it would probably be best to align on throwing in both cases in a separate major bump.

@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Review requested:

  • @nodejs/http
  • @nodejs/http2
  • @nodejs/net

@nodejs-github-botnodejs-github-bot added http Issues or PRs related to the http subsystem. http2 Issues or PRs related to the http2 subsystem. needs-ci PRs that need a full CI run. labels May 6, 2026
@codecov

codecovBot commented May 6, 2026

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 90.47619% with 8 lines in your changes missing coverage. Please review.
✅ Project coverage is 90.02%. Comparing base (b5da751) to head (af03c6b).
⚠️ Report is 61 commits behind head on main.

Files with missing linesPatch %Lines
lib/_http_server.js85.45%8 Missing ⚠️
Additional details and impacted files
@@ Coverage Diff @@## main #63155 +/- ##
==========================================
- Coverage 90.03% 90.02% -0.02% 
==========================================
Files 713 713 Lines 224510 224565 +55 Branches 42438 42462 +24 ==========================================
+ Hits 202148 202161 +13 - Misses 14163 14222 +59 + Partials 8199 8182 -17 
Files with missing linesCoverage Δ
lib/internal/http2/compat.js97.10% <100.00%> (+0.13%)⬆️
lib/_http_server.js96.61% <85.45%> (-0.33%)⬇️

... and 31 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@metcoder95metcoder95 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Don't have approval power, but lgtm; nice addition

Signed-off-by: Tim Perry <pimterry@gmail.com>
@pimterry
pimterryforce-pushed the h1-additional-headers branch from d6b58d7 to af03c6bCompareMay 7, 2026 08:20
@pimterry

Copy link
Copy Markdown
MemberAuthor

Rebased to hopefully fix the build now that the QUIC coverage issue is sorted.

@mcollinamcollina left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm

@mcollinamcollina added the request-ci Add this label to start a Jenkins CI on a PR. label May 15, 2026
@github-actionsgithub-actionsBot removed the request-ci Add this label to start a Jenkins CI on a PR. label May 15, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@pimterrypimterry added the semver-minor PRs that contain new features and should be released in the next minor version. label May 15, 2026
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

@pimterrypimterry added the commit-queue Add this label to land a pull request using GitHub Actions. label May 15, 2026
@nodejs-github-botnodejs-github-bot removed the commit-queue Add this label to land a pull request using GitHub Actions. label May 15, 2026
@nodejs-github-bot
nodejs-github-bot merged commit 03f27fe into nodejs:mainMay 15, 2026
76 checks passed
@nodejs-github-bot

Copy link
Copy Markdown
Collaborator

Landed in 03f27fe

aduh95 pushed a commit that referenced this pull request May 19, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #63155
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Ethan Arrowood <ethan@arrowood.dev>
aduh95 pushed a commit that referenced this pull request May 19, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #63155
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Ethan Arrowood <ethan@arrowood.dev>
nodejs-github-bot added a commit that referenced this pull request May 19, 2026
Notable changes:
doc:
* mark stream.compose stable (Matteo Collina) #62562
fs:
* (SEMVER-MINOR) add `Temporal.Instant` support to `Stats` and `BigIntStats` (Livia Medeiros) #60789
http:
* (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155
PR-URL: #63440
aduh95 added a commit that referenced this pull request May 20, 2026
Notable changes:
doc:
* mark `stream.compose` stable (Matteo Collina) #62562
fs:
* (SEMVER-MINOR) add `Temporal.Instant` support to `Stats` and `BigIntStats` (Livia Medeiros) #60789
http:
* (SEMVER-MINOR) add `writeInformation` to send arbitrary 1xx status codes (Tim Perry) #63155
PR-URL: #63440
aduh95 added a commit that referenced this pull request May 20, 2026
Notable changes:
doc:
* mark `stream.compose` stable (Matteo Collina) #62562
fs:
* (SEMVER-MINOR) add `Temporal.Instant` support to `Stats` and `BigIntStats` (Livia Medeiros) #60789
http:
* (SEMVER-MINOR) add `writeInformation` to send arbitrary 1xx status codes (Tim Perry) #63155
PR-URL: #63440
aduh95 pushed a commit that referenced this pull request May 23, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #63155
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Ethan Arrowood <ethan@arrowood.dev>
aduh95 pushed a commit that referenced this pull request Jun 18, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: #63155
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Ethan Arrowood <ethan@arrowood.dev>
nodejs-github-bot added a commit that referenced this pull request Jun 19, 2026
Notable changes:
buffer:
* (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597
crypto:
* update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527
http:
* (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155
inspector:
* (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079
PR-URL: #64001
sxa added a commit that referenced this pull request Jun 22, 2026
Notable changes:
* crypto: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527
* (SEMVER-MINOR) buffer: increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597
* (SEMVER-MINOR) crypto: align key argument names in docs and error messages (Filip Skokan) #62527
* (SEMVER-MINOR) crypto: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #62527
* (SEMVER-MINOR) crypto: unify asymmetric key import through KeyObjectHandle::Init (Filip Skokan) #62499
* (SEMVER-MINOR) crypto: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #62183
* (SEMVER-MINOR) http: add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155
* (SEMVER-MINOR) inspector: expose precise coverage start to JS runtime (sangwook) #63079
* (SEMVER-MINOR) lib: cleanup stateless diffiehellman key handling (Filip Skokan) #62645
PR-URL: #64062
sxa added a commit that referenced this pull request Jun 22, 2026
Notable changes:
buffer:
* (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597
crypto:
* update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527
* (SEMVER-MINOR) align key argument names in docs and error messages (Filip Skokan) #62527
* (SEMVER-MINOR) accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #62527
* (SEMVER-MINOR) add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #62183
http:
* http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004
* (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155
inspector:
* (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079
stream:
* stream: Revert noop pause/resume on destroyed streams" (Stewart X Addison) #63834
PR-URL: #64062
sxa added a commit to sxa/node that referenced this pull request Jun 23, 2026
Notable changes:
buffer:
* (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) nodejs#63597
crypto:
* update root certificates to NSS 3.123.1 (Node.js GitHub Bot) nodejs#63527
* (SEMVER-MINOR) align key argument names in docs and error messages (Filip Skokan) nodejs#62527
* (SEMVER-MINOR) accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) nodejs#62527
* (SEMVER-MINOR) add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) nodejs#62183
http:
* http: avoid stream listeners on idle agent sockets (Matteo Collina) nodejs#64004
* (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) nodejs#63155
inspector:
* (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) nodejs#63079
stream:
* stream: Revert noop pause/resume on destroyed streams" (Stewart X Addison) nodejs#63834
PR-URL: nodejs#64062
richardlau pushed a commit that referenced this pull request Jun 23, 2026
Notable changes:
buffer:
* (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597
crypto:
* update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527
* (SEMVER-MINOR) align key argument names in docs and error messages (Filip Skokan) #62527
* (SEMVER-MINOR) accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) #62527
* (SEMVER-MINOR) add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) #62183
http:
* http: avoid stream listeners on idle agent sockets (Matteo Collina) #64004
* (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155
inspector:
* (SEMVER-MINOR) expose precise coverage start to JS runtime (sangwook) #63079
stream:
* stream: Revert noop pause/resume on destroyed streams" (Stewart X Addison) #63834
PR-URL: #64062
mwalbeck pushed a commit to mwalbeck/docker-cyberchef that referenced this pull request Jul 11, 2026
This PR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| [node](https://github.com/nodejs/node) | stage | minor | `24.16.0-trixie` → `24.18.0-trixie` |
---
### Release Notes
<details>
<summary>nodejs/node (node)</summary>
### [`v24.18.0`](https://github.com/nodejs/node/releases/tag/v24.18.0): 2026-06-23, Version 24.18.0 'Krypton' (LTS), @&#8203;richardlau prepared by @&#8203;sxa
[Compare Source](nodejs/node@v24.17.0...v24.18.0)
##### Notable Changes
- \[[`e07e7a31e1`](nodejs/node@e07e7a31e1)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#&#8203;63527](nodejs/node#63527)
- \[[`44c8ebcbd6`](nodejs/node@44c8ebcbd6)] - **http**: avoid stream listeners on idle agent sockets (Matteo Collina) [#&#8203;64004](nodejs/node#64004)
- \[[`d3ef4122ee`](nodejs/node@d3ef4122ee)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#&#8203;63597](nodejs/node#63597)
- \[[`bb2857b85a`](nodejs/node@bb2857b85a)] - **(SEMVER-MINOR)** **crypto**: align key argument names in docs and error messages (Filip Skokan) [#&#8203;62527](nodejs/node#62527)
- \[[`b9d5e87880`](nodejs/node@b9d5e87880)] - **(SEMVER-MINOR)** **crypto**: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) [#&#8203;62527](nodejs/node#62527)
- \[[`ccd756d61e`](nodejs/node@ccd756d61e)] - **(SEMVER-MINOR)** **crypto**: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) [#&#8203;62183](nodejs/node#62183)
- \[[`4c9251fc09`](nodejs/node@4c9251fc09)] - **(SEMVER-MINOR)** **http**: add writeInformation to send arbitrary 1xx status codes (Tim Perry) [#&#8203;63155](nodejs/node#63155)
- \[[`8c989ec4a3`](nodejs/node@8c989ec4a3)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#&#8203;63079](nodejs/node#63079)
- \[[`3f54c8ba32`](nodejs/node@3f54c8ba32)] - ***Revert*** "**stream**: noop pause/resume on destroyed streams" (Stewart X Addison) [#&#8203;63834](nodejs/node#63834)
##### Commits
- \[[`d3ef4122ee`](nodejs/node@d3ef4122ee)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#&#8203;63597](nodejs/node#63597)
- \[[`9ff36e40f0`](nodejs/node@9ff36e40f0)] - **build**: add --enable-all-experimentals build flag (Paolo Insogna) [#&#8203;62755](nodejs/node#62755)
- \[[`7c22ee23aa`](nodejs/node@7c22ee23aa)] - **build**: def `NODE_USE_NODE_CODE_CACHE` only used in node\_mksnapshot (Chengzhong Wu) [#&#8203;63588](nodejs/node#63588)
- \[[`2551abdb4a`](nodejs/node@2551abdb4a)] - **build,win**: enable x64 PGO (Stefan Stojanovic) [#&#8203;62761](nodejs/node#62761)
- \[[`e8a55ce9b1`](nodejs/node@e8a55ce9b1)] - **crypto**: strengthen argument CHECKs in TurboSHAKE (Tobias Nießen) [#&#8203;62763](nodejs/node#62763)
- \[[`ae61cd68f3`](nodejs/node@ae61cd68f3)] - **crypto**: harden WebCrypto against prototype pollution (Filip Skokan) [#&#8203;63363](nodejs/node#63363)
- \[[`3d05a1d396`](nodejs/node@3d05a1d396)] - **crypto**: pass CryptoKey handles to KDF jobs (Filip Skokan) [#&#8203;63363](nodejs/node#63363)
- \[[`f9d10a3f6b`](nodejs/node@f9d10a3f6b)] - **crypto**: remove async from WebCrypto methods (Filip Skokan) [#&#8203;63363](nodejs/node#63363)
- \[[`e431d93e9e`](nodejs/node@e431d93e9e)] - **crypto**: add WebCrypto CryptoJob mode (Filip Skokan) [#&#8203;63363](nodejs/node#63363)
- \[[`56e2505e48`](nodejs/node@56e2505e48)] - **crypto**: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) [#&#8203;63255](nodejs/node#63255)
- \[[`3bac77f2a8`](nodejs/node@3bac77f2a8)] - **crypto**: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) [#&#8203;63255](nodejs/node#63255)
- \[[`1bff901b09`](nodejs/node@1bff901b09)] - **crypto**: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) [#&#8203;63255](nodejs/node#63255)
- \[[`4433fca3df`](nodejs/node@4433fca3df)] - **crypto**: harden CryptoKey algorithm slots (Filip Skokan) [#&#8203;63111](nodejs/node#63111)
- \[[`b5cf01217a`](nodejs/node@b5cf01217a)] - **crypto**: harden KeyObject internal slots (Filip Skokan) [#&#8203;63111](nodejs/node#63111)
- \[[`ce84aef37d`](nodejs/node@ce84aef37d)] - **crypto**: add guards and adjust tests for BoringSSL (Filip Skokan) [#&#8203;62883](nodejs/node#62883)
- \[[`26781689b0`](nodejs/node@26781689b0)] - **crypto**: reject duplicate ML-KEM JWK key\_ops (Filip Skokan) [#&#8203;62905](nodejs/node#62905)
- \[[`aeea8f4970`](nodejs/node@aeea8f4970)] - **crypto**: add JWK support for ML-KEM and SLH-DSA key types (Filip Skokan) [#&#8203;62706](nodejs/node#62706)
- \[[`407cf91656`](nodejs/node@407cf91656)] - **crypto**: guard against size\_t overflow on experimental 32-bit arch (Filip Skokan) [#&#8203;62626](nodejs/node#62626)
- \[[`bb2857b85a`](nodejs/node@bb2857b85a)] - **(SEMVER-MINOR)** **crypto**: align key argument names in docs and error messages (Filip Skokan) [#&#8203;62527](nodejs/node#62527)
- \[[`b9d5e87880`](nodejs/node@b9d5e87880)] - **(SEMVER-MINOR)** **crypto**: accept key data in crypto.diffieHellman() and cleanup DH jobs (Filip Skokan) [#&#8203;62527](nodejs/node#62527)
- \[[`b46d52b283`](nodejs/node@b46d52b283)] - **crypto**: unify asymmetric key import through KeyObjectHandle::Init (Filip Skokan) [#&#8203;62499](nodejs/node#62499)
- \[[`ccd756d61e`](nodejs/node@ccd756d61e)] - **(SEMVER-MINOR)** **crypto**: add TurboSHAKE and KangarooTwelve Web Cryptography algorithms (Filip Skokan) [#&#8203;62183](nodejs/node#62183)
- \[[`e07e7a31e1`](nodejs/node@e07e7a31e1)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#&#8203;63527](nodejs/node#63527)
- \[[`61826df455`](nodejs/node@61826df455)] - **crypto**: coerce -0 keylen to +0 in pbkdf2 and scrypt (Jordan Harband) [#&#8203;63531](nodejs/node#63531)
- \[[`16d2fd3c07`](nodejs/node@16d2fd3c07)] - **crypto**: align verifyOneShot accepted types (Anshika Jain) [#&#8203;63280](nodejs/node#63280)
- \[[`3b8330deda`](nodejs/node@3b8330deda)] - **crypto**: improve system certificate enumeration logic on macOS (Robo) [#&#8203;62576](nodejs/node#62576)
- \[[`141de35399`](nodejs/node@141de35399)] - **debugger**: add --help to `node inspect` and improve docs (Joyee Cheung) [#&#8203;63201](nodejs/node#63201)
- \[[`b76bfcd4fa`](nodejs/node@b76bfcd4fa)] - **deps**: upgrade npm to 11.16.0 (npm team) [#&#8203;63602](nodejs/node#63602)
- \[[`4ec142314c`](nodejs/node@4ec142314c)] - **deps**: SQLite: cherry-pick [`b869ed6`](nodejs/node@b869ed6) (Junsu Han) [#&#8203;63525](nodejs/node#63525)
- \[[`19e8ce1c36`](nodejs/node@19e8ce1c36)] - **deps**: upgrade npm to 11.15.0 (npm team) [#&#8203;63463](nodejs/node#63463)
- \[[`8a264260e2`](nodejs/node@8a264260e2)] - **deps**: update sqlite to 3.53.1 (Node.js GitHub Bot) [#&#8203;63217](nodejs/node#63217)
- \[[`50c8ff3f94`](nodejs/node@50c8ff3f94)] - **deps**: update simdjson to 4.6.4 (Node.js GitHub Bot) [#&#8203;62811](nodejs/node#62811)
- \[[`6e56f01c4b`](nodejs/node@6e56f01c4b)] - **deps**: V8: cherry-pick [`435a2cd`](nodejs/node@435a2cdf664c) (Matthias Liedtke) [#&#8203;63136](nodejs/node#63136)
- \[[`3ba813b242`](nodejs/node@3ba813b242)] - **deps**: cherry-pick [libuv/libuv@`a43e543`](libuv/libuv@a43e543) (Ali Hassan) [#&#8203;63222](nodejs/node#63222)
- \[[`2390e3a5ac`](nodejs/node@2390e3a5ac)] - **doc**: remove duplicated sentences in large-pull-requests.md (Joyee Cheung) [#&#8203;63650](nodejs/node#63650)
- \[[`52a1c18374`](nodejs/node@52a1c18374)] - **doc**: update `git node land` instructions for security releases (Antoine du Hamel) [#&#8203;63586](nodejs/node#63586)
- \[[`3e6b4da037`](nodejs/node@3e6b4da037)] - **doc**: drop --experimental from --permission (Rafael Gonzaga) [#&#8203;63583](nodejs/node#63583)
- \[[`84d05163b9`](nodejs/node@84d05163b9)] - **doc**: explicitly ask for reproducible in JS (Rafael Gonzaga) [#&#8203;63479](nodejs/node#63479)
- \[[`7da2a4450e`](nodejs/node@7da2a4450e)] - **doc**: fix URL postMessage example in worker\_threads (Kit Dallege) [#&#8203;62203](nodejs/node#62203)
- \[[`3d79bd8b29`](nodejs/node@3d79bd8b29)] - **doc**: clarify `filter` option of `sqlite.database.applyChangeset` (Antoine du Hamel) [#&#8203;63515](nodejs/node#63515)
- \[[`4f4174aace`](nodejs/node@4f4174aace)] - **doc**: fix double spaces in ERR\_TLS\_INVALID\_PROTOCOL\_METHOD (Daijiro Wachi) [#&#8203;63511](nodejs/node#63511)
- \[[`388323ca4b`](nodejs/node@388323ca4b)] - **doc**: fix double space in modules.md (Daijiro Wachi) [#&#8203;63512](nodejs/node#63512)
- \[[`5258ccc058`](nodejs/node@5258ccc058)] - **doc**: fix "options" to "option" in tls.createServer (Daijiro Wachi) [#&#8203;63453](nodejs/node#63453)
- \[[`43e83e6507`](nodejs/node@43e83e6507)] - **doc**: fix typo in deprecations (Daijiro Wachi) [#&#8203;63434](nodejs/node#63434)
- \[[`f05a61d54c`](nodejs/node@f05a61d54c)] - **doc**: remove unsupported template type from v8.md (René) [#&#8203;63410](nodejs/node#63410)
- \[[`c39d5fc820`](nodejs/node@c39d5fc820)] - **doc**: fix article usage before vowel-sound acronyms (joao-oliveira-softtor) [#&#8203;62696](nodejs/node#62696)
- \[[`398261f911`](nodejs/node@398261f911)] - **doc**: remove the bi-monthly contributor spotlight section (Claudio Wunder) [#&#8203;62734](nodejs/node#62734)
- \[[`fd9e14c405`](nodejs/node@fd9e14c405)] - **doc**: update http2's `push` and `trailers` events with `rawHeaders` param (YuSheng Chen) [#&#8203;63259](nodejs/node#63259)
- \[[`b943ce6933`](nodejs/node@b943ce6933)] - **doc**: remove inactive members from Triagers list (Antoine du Hamel) [#&#8203;63329](nodejs/node#63329)
- \[[`4b9cdfc022`](nodejs/node@4b9cdfc022)] - **doc**: reference correct function in Module docs (Robin Malfait) [#&#8203;63247](nodejs/node#63247)
- \[[`bed84b6df2`](nodejs/node@bed84b6df2)] - **doc**: replace Visual Studio 2022 Evergreen version reference with 17.14 (Mike McCready) [#&#8203;63211](nodejs/node#63211)
- \[[`32ea70569b`](nodejs/node@32ea70569b)] - **doc**: recommend explicitly Tier 1 or 2 for production applications (Mike McCready) [#&#8203;63187](nodejs/node#63187)
- \[[`4627bcfd82`](nodejs/node@4627bcfd82)] - **doc**: run license-builder (github-actions\[bot]) [#&#8203;63232](nodejs/node#63232)
- \[[`28eba71845`](nodejs/node@28eba71845)] - **doc**: add large pull requests contributing guide (Matteo Collina) [#&#8203;62829](nodejs/node#62829)
- \[[`2648efd438`](nodejs/node@2648efd438)] - **doc**: remove unnecessary `<!-- eslint-` magic comments (Antoine du Hamel) [#&#8203;63200](nodejs/node#63200)
- \[[`a95fc1f8fc`](nodejs/node@a95fc1f8fc)] - **doc**: clarify SEA platform support excludes darwin-x64 (MJSHANG) [#&#8203;63181](nodejs/node#63181)
- \[[`aaef29e2e1`](nodejs/node@aaef29e2e1)] - **doc**: update release steps when post-release fails (Rafael Gonzaga) [#&#8203;63131](nodejs/node#63131)
- \[[`7d81419cf2`](nodejs/node@7d81419cf2)] - **doc**: add Hmac.digest() documentation-only deprecation (DEP0206) (Anshika Jain) [#&#8203;63121](nodejs/node#63121)
- \[[`ececd80d81`](nodejs/node@ececd80d81)] - **doc**: document the latest-vX.x schema (Marco Ippolito) [#&#8203;63033](nodejs/node#63033)
- \[[`27c1c1d842`](nodejs/node@27c1c1d842)] - **doc**: remove list of versions in `BUILDING.md` (Antoine du Hamel) [#&#8203;63113](nodejs/node#63113)
- \[[`e369886a65`](nodejs/node@e369886a65)] - **doc,sqlite**: document entryPoint argument for loadExtension (Edy Silva) [#&#8203;63152](nodejs/node#63152)
- \[[`e4e5137cbd`](nodejs/node@e4e5137cbd)] - **errors**: handle V8 warnings in DisallowJavascriptExecutionScope (Divyanshu Sharma) [#&#8203;63491](nodejs/node#63491)
- \[[`6d1f6048d2`](nodejs/node@6d1f6048d2)] - **fs**: make `Date` properties on `Stats` enumerable (LiviaMedeiros) [#&#8203;63328](nodejs/node#63328)
- \[[`44c8ebcbd6`](nodejs/node@44c8ebcbd6)] - **http**: avoid stream listeners on idle agent sockets (Matteo Collina) [#&#8203;64004](nodejs/node#64004)
- \[[`4c9251fc09`](nodejs/node@4c9251fc09)] - **(SEMVER-MINOR)** **http**: add writeInformation to send arbitrary 1xx status codes (Tim Perry) [#&#8203;63155](nodejs/node#63155)
- \[[`39f61fb06c`](nodejs/node@39f61fb06c)] - **http2**: emit session close before stream close (Matteo Collina) [#&#8203;63414](nodejs/node#63414)
- \[[`8a8f2127d1`](nodejs/node@8a8f2127d1)] - **http2**: validate non-link headers in writeEarlyHints (Matteo Collina) [#&#8203;62017](nodejs/node#62017)
- \[[`8c989ec4a3`](nodejs/node@8c989ec4a3)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#&#8203;63079](nodejs/node#63079)
- \[[`c05f38229b`](nodejs/node@c05f38229b)] - **lib**: cleanup stateless diffiehellman key handling (Filip Skokan) [#&#8203;62645](nodejs/node#62645)
- \[[`1c16b45d35`](nodejs/node@1c16b45d35)] - **lib**: refactor internal webidl converters (Filip Skokan) [#&#8203;62979](nodejs/node#62979)
- \[[`02f35d6dce`](nodejs/node@02f35d6dce)] - **lib**: define `kEnumerableProperty` atomically (Antoine du Hamel) [#&#8203;63609](nodejs/node#63609)
- \[[`12c51547ba`](nodejs/node@12c51547ba)] - **lib**: fix typos in esm loader comments (RonGamzu) [#&#8203;63465](nodejs/node#63465)
- \[[`9b03b84262`](nodejs/node@9b03b84262)] - **lib**: fix typo idenity => identity (Daijiro Wachi) [#&#8203;63112](nodejs/node#63112)
- \[[`a84e6b0567`](nodejs/node@a84e6b0567)] - **lib**: fixes validator message (Daijiro Wachi) [#&#8203;62823](nodejs/node#62823)
- \[[`11734166a8`](nodejs/node@11734166a8)] - **lib**: narrow ReadableStreamBYOBRequest.view return type to Uint8Array (RoomWithOutRoof) [#&#8203;63017](nodejs/node#63017)
- \[[`7cead61d21`](nodejs/node@7cead61d21)] - **meta**: flip mcollina emails in .mailmap (Matteo Collina) [#&#8203;63621](nodejs/node#63621)
- \[[`a08cfcfd35`](nodejs/node@a08cfcfd35)] - **meta**: label "source maps" PRs (Chengzhong Wu) [#&#8203;63591](nodejs/node#63591)
- \[[`d56e8d2512`](nodejs/node@d56e8d2512)] - **meta**: add `vfs` subsystem label (René) [#&#8203;62331](nodejs/node#62331)
- \[[`6201cfe488`](nodejs/node@6201cfe488)] - **meta**: skip scheduled workflows on forks (Jamie Magee) [#&#8203;63565](nodejs/node#63565)
- \[[`f095e2bd31`](nodejs/node@f095e2bd31)] - **meta**: add additional gitignore entries (James M Snell) [#&#8203;63267](nodejs/node#63267)
- \[[`1ea52c444c`](nodejs/node@1ea52c444c)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#&#8203;63402](nodejs/node#63402)
- \[[`b1b2327611`](nodejs/node@b1b2327611)] - **meta**: move one or more collaborators to emeritus (Node.js GitHub Bot) [#&#8203;63235](nodejs/node#63235)
- \[[`7d88e130a9`](nodejs/node@7d88e130a9)] - **meta**: ignore AI assistants files (Matteo Collina) [#&#8203;62612](nodejs/node#62612)
- \[[`a53b51df38`](nodejs/node@a53b51df38)] - **module**: load ESM helpers eagerly in the snapshot (Joyee Cheung) [#&#8203;63550](nodejs/node#63550)
- \[[`69df688fff`](nodejs/node@69df688fff)] - **module**: fix sync hook short-circuit in require() in imported CJS (Joyee Cheung) [#&#8203;62920](nodejs/node#62920)
- \[[`75d9a4ed47`](nodejs/node@75d9a4ed47)] - **node-api**: support SharedArrayBuffer in napi\_create\_typedarray (Yilong Li) [#&#8203;62710](nodejs/node#62710)
- \[[`c20aa4c47b`](nodejs/node@c20aa4c47b)] - **quic**: add reusePort option to QuicEndpoint (James M Snell) [#&#8203;63267](nodejs/node#63267)
- \[[`26a30d8a7f`](nodejs/node@26a30d8a7f)] - **quic**: implement rate limiting for version nego and immediate close (James M Snell) [#&#8203;63267](nodejs/node#63267)
- \[[`0b534b5770`](nodejs/node@0b534b5770)] - **quic**: fixup linting issue after other changes (James M Snell) [#&#8203;63267](nodejs/node#63267)
- \[[`4b367cbe09`](nodejs/node@4b367cbe09)] - **quic**: remove unused binding variable in session.cc (James M Snell) [#&#8203;63177](nodejs/node#63177)
- \[[`2574bef5a6`](nodejs/node@2574bef5a6)] - **repl**: fix dedup comparing normalized line against raw history (Daijiro Wachi) [#&#8203;62886](nodejs/node#62886)
- \[[`30e71c7e49`](nodejs/node@30e71c7e49)] - **sqlite**: keep source database alive during backup (Matteo Collina) [#&#8203;62673](nodejs/node#62673)
- \[[`677ca7e76c`](nodejs/node@677ca7e76c)] - **src**: simplify OpenSSL feature gates (Filip Skokan) [#&#8203;63255](nodejs/node#63255)
- \[[`c863c75c39`](nodejs/node@c863c75c39)] - **src**: add BoringSSL EVP enumeration fallback (Filip Skokan) [#&#8203;63206](nodejs/node#63206)
- \[[`f6b2466921`](nodejs/node@f6b2466921)] - **src**: decouple KeyObject and CryptoKey and move CryptoKey to src (Filip Skokan) [#&#8203;62924](nodejs/node#62924)
- \[[`92d4f07dd2`](nodejs/node@92d4f07dd2)] - **src**: remove license headers for new node\_profiling files (Chengzhong Wu) [#&#8203;63066](nodejs/node#63066)
- \[[`8ac5d771c8`](nodejs/node@8ac5d771c8)] - **src**: split profiling helpers from util (Ilyas Shabi) [#&#8203;63008](nodejs/node#63008)
- \[[`85d1639495`](nodejs/node@85d1639495)] - **src**: remove TOCTOU race condition when encoding SAB-backed `Buffer`s (Antoine du Hamel) [#&#8203;63517](nodejs/node#63517)
- \[[`9473c5f05c`](nodejs/node@9473c5f05c)] - **src**: skip duplicate UTF-8 validation in TextDecoder fatal path (Mert Can Altin) [#&#8203;63231](nodejs/node#63231)
- \[[`f35c91ee68`](nodejs/node@f35c91ee68)] - **src**: improve token return value check (James M Snell) [#&#8203;63483](nodejs/node#63483)
- \[[`26f677c1c5`](nodejs/node@26f677c1c5)] - **src**: expose `node::RegisterContext` to make a node managed context (Chengzhong Wu) [#&#8203;62322](nodejs/node#62322)
- \[[`275cf909b6`](nodejs/node@275cf909b6)] - **src,sqlite**: only pass `xFilter` when user provided a callback (Antoine du Hamel) [#&#8203;63516](nodejs/node#63516)
- \[[`287e02303f`](nodejs/node@287e02303f)] - **src,sqlite**: remove dead code (Edy Silva) [#&#8203;63204](nodejs/node#63204)
- \[[`58fa2ee189`](nodejs/node@58fa2ee189)] - **stream**: switch to internal `sleep` binding (Antoine du Hamel) [#&#8203;63611](nodejs/node#63611)
- \[[`f954ab3f1a`](nodejs/node@f954ab3f1a)] - **stream**: use data listener for compose forwarding (Trivikram Kamat) [#&#8203;63593](nodejs/node#63593)
- \[[`dc57173003`](nodejs/node@dc57173003)] - **stream**: fix Writable.toWeb() hang on synchronous drain (sangwook) [#&#8203;61197](nodejs/node#61197)
- \[[`3f54c8ba32`](nodejs/node@3f54c8ba32)] - ***Revert*** "**stream**: noop pause/resume on destroyed streams" (Stewart X Addison) [#&#8203;63834](nodejs/node#63834)
- \[[`cee279c5d6`](nodejs/node@cee279c5d6)] - **stream**: remove unnecessary check (Antoine du Hamel) [#&#8203;63030](nodejs/node#63030)
- \[[`61b20f60a3`](nodejs/node@61b20f60a3)] - **test**: update tls/crypto behaviour expectations when using BoringSSL (Filip Skokan) [#&#8203;63161](nodejs/node#63161)
- \[[`a835363808`](nodejs/node@a835363808)] - **test**: update WPT for WebCryptoAPI to [`97bbc72`](nodejs/node@97bbc7247a) (Node.js GitHub Bot) [#&#8203;63417](nodejs/node#63417)
- \[[`a00297480b`](nodejs/node@a00297480b)] - **test**: update WPT resources, interfaces and WebCryptoAPI (Node.js GitHub Bot) [#&#8203;62389](nodejs/node#62389)
- \[[`5a95a2b055`](nodejs/node@5a95a2b055)] - **test**: shorten path in net pipe connect errors (Matteo Collina) [#&#8203;63405](nodejs/node#63405)
- \[[`5e8ff22d8f`](nodejs/node@5e8ff22d8f)] - **test**: remove test-node-output-v8-warning (Joyee Cheung) [#&#8203;63469](nodejs/node#63469)
- \[[`ee15380950`](nodejs/node@ee15380950)] - **test**: update test426-fixtures to [`9b9e225`](nodejs/node@9b9e225) (Node.js GitHub Bot) [#&#8203;63373](nodejs/node#63373)
- \[[`9e063d9bea`](nodejs/node@9e063d9bea)] - **test**: update WPT for url to [`e4a4672`](nodejs/node@e4a4672e9e) (Node.js GitHub Bot) [#&#8203;63372](nodejs/node#63372)
- \[[`503bee4b43`](nodejs/node@503bee4b43)] - **test**: deflake async-hooks statwatcher test (Trivikram Kamat) [#&#8203;63396](nodejs/node#63396)
- \[[`cccc7c32d8`](nodejs/node@cccc7c32d8)] - **test**: avoid test\_runner watch restart in spec snapshot (Trivikram Kamat) [#&#8203;63392](nodejs/node#63392)
- \[[`c89489258c`](nodejs/node@c89489258c)] - **test**: reduce watch mode restart flakiness (Trivikram Kamat) [#&#8203;63390](nodejs/node#63390)
- \[[`e4d5e2578e`](nodejs/node@e4d5e2578e)] - **test**: isolate rerun-failures state file under tmpdir (Chemi Atlow) [#&#8203;63449](nodejs/node#63449)
- \[[`362644a9ba`](nodejs/node@362644a9ba)] - **test**: wait for ok before initial break after restart (Yuya Inoue) [#&#8203;62807](nodejs/node#62807)
- \[[`c4058d0e05`](nodejs/node@c4058d0e05)] - **test**: disable Maglev in near-heap-limit worker test (Trivikram Kamat) [#&#8203;63398](nodejs/node#63398)
- \[[`214da630a7`](nodejs/node@214da630a7)] - **test**: deflake connection refused proxy tests (Trivikram Kamat) [#&#8203;63395](nodejs/node#63395)
- \[[`1d61a29876`](nodejs/node@1d61a29876)] - **test**: avoid repeated writes in watch helper (Trivikram Kamat) [#&#8203;63386](nodejs/node#63386)
- \[[`2004e25387`](nodejs/node@2004e25387)] - **test**: deflake watch mode worker test (Trivikram Kamat) [#&#8203;63384](nodejs/node#63384)
- \[[`d691cccfc1`](nodejs/node@d691cccfc1)] - **test**: relax test-memory-usage arrayBuffers check (inoway46) [#&#8203;63244](nodejs/node#63244)
- \[[`0ff6bf853c`](nodejs/node@0ff6bf853c)] - **test**: reduce flakiness of `different-registry-per-thread` (Antoine du Hamel) [#&#8203;63244](nodejs/node#63244)
- \[[`d9f4e8e503`](nodejs/node@d9f4e8e503)] - **test**: fix flaky test-watch-mode-inspect timeout (Matteo Collina) [#&#8203;63361](nodejs/node#63361)
- \[[`6d7cd50328`](nodejs/node@6d7cd50328)] - **test**: relax min assertion in test-performance-eventloopdelay (Marco) [#&#8203;63100](nodejs/node#63100)
- \[[`9dafe1d2d8`](nodejs/node@9dafe1d2d8)] - **test**: avoid flaky restart sync in debugger exceptions test (Yuya Inoue) [#&#8203;62055](nodejs/node#62055)
- \[[`989b2de973`](nodejs/node@989b2de973)] - **test**: avoid initial-break wait in restart-message (inoway46) [#&#8203;62060](nodejs/node#62060)
- \[[`a072a25ee7`](nodejs/node@a072a25ee7)] - **test**: move FFI tests to `NATIVE_SUITES` (Antoine du Hamel) [#&#8203;63165](nodejs/node#63165)
- \[[`64efbfd878`](nodejs/node@64efbfd878)] - **test**: use ERM to destroy sqlite database handles after tests (René) [#&#8203;63076](nodejs/node#63076)
- \[[`7dee66cd94`](nodejs/node@7dee66cd94)] - **test\_runner**: dont buffer unordered events in process isolation mode (Moshe Atlow) [#&#8203;63432](nodejs/node#63432)
- \[[`d257eec1e3`](nodejs/node@d257eec1e3)] - **test\_runner**: fix --test-rerun-failures swallowing failures on retry (Chemi Atlow) [#&#8203;63431](nodejs/node#63431)
- \[[`288c320e2f`](nodejs/node@288c320e2f)] - **test\_runner**: show replayed-from-attempt hint in spec reporter (Moshe Atlow) [#&#8203;63429](nodejs/node#63429)
- \[[`904bdf5bb4`](nodejs/node@904bdf5bb4)] - **test\_runner**: preserve run duration when using test-rerun (Moshe Atlow) [#&#8203;63429](nodejs/node#63429)
- \[[`df183d7bfa`](nodejs/node@df183d7bfa)] - **test\_runner**: avoid hanging on incomplete v8 frames (Ali Hassan) [#&#8203;62704](nodejs/node#62704)
- \[[`ec86c69726`](nodejs/node@ec86c69726)] - **test\_runner**: fix diagnostics channel context tracking (Moshe Atlow) [#&#8203;63283](nodejs/node#63283)
- \[[`94e5f63b83`](nodejs/node@94e5f63b83)] - **tls**: add unsupported renegotiation error (Filip Skokan) [#&#8203;63161](nodejs/node#63161)
- \[[`06d308fb61`](nodejs/node@06d308fb61)] - **tools**: prevent lib code from reading KeyObject and CryptoKey accessors (Filip Skokan) [#&#8203;63111](nodejs/node#63111)
- \[[`2e4a0d0c91`](nodejs/node@2e4a0d0c91)] - **tools**: bump brace-expansion from 5.0.5 to 5.0.6 in /tools/eslint (dependabot\[bot]) [#&#8203;63415](nodejs/node#63415)
- \[[`4c9666b366`](nodejs/node@4c9666b366)] - **tools**: skip commit-lint on backport pull requests (Marco) [#&#8203;63378](nodejs/node#63378)
- \[[`67d0c490a8`](nodejs/node@67d0c490a8)] - **tools**: fix skip of `test-internet` on forks (Antoine du Hamel) [#&#8203;63492](nodejs/node#63492)
- \[[`02f73c7cac`](nodejs/node@02f73c7cac)] - **tools**: bump the eslint group in /tools/eslint with 4 updates (dependabot\[bot]) [#&#8203;63075](nodejs/node#63075)
- \[[`5d016d3241`](nodejs/node@5d016d3241)] - **tools**: update gyp-next to 0.22.2 (Node.js GitHub Bot) [#&#8203;63374](nodejs/node#63374)
- \[[`55af0f0edb`](nodejs/node@55af0f0edb)] - **tools**: fix test426 updater (Antoine du Hamel) [#&#8203;63271](nodejs/node#63271)
- \[[`d8475e167a`](nodejs/node@d8475e167a)] - **tools**: use different branch for tool updates on staging branches (Antoine du Hamel) [#&#8203;63110](nodejs/node#63110)
- \[[`c605df9e50`](nodejs/node@c605df9e50)] - **util**: remove unused functions (Antoine du Hamel) [#&#8203;63612](nodejs/node#63612)
- \[[`fe4540ebdb`](nodejs/node@fe4540ebdb)] - **util**: create hex style cache and fast path (Guilherme Araújo) [#&#8203;62999](nodejs/node#62999)
### [`v24.17.0`](https://github.com/nodejs/node/releases/tag/v24.17.0): 2026-06-18, Version 24.17.0 'Krypton' (LTS), @&#8203;aduh95
[Compare Source](nodejs/node@v24.16.0...v24.17.0)
This is a security release.
##### Notable Changes
- (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
- (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
- (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
- (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
- (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
- (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
- (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
- (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 – Medium
- (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
- (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
- (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
##### Commits
- \[[`9e4dfc7bba`](nodejs/node@9e4dfc7bba)] - **(CVE-2026-48933)** **crypto**: guard WebCrypto cipher output length (Filip Skokan) [nodejs-private/node-private#878](https://github.com/nodejs-private/node-private/pull/878)
- \[[`cb2aed980c`](nodejs/node@cb2aed980c)] - **deps**: update llhttp to 9.4.2 (Antoine du Hamel) [nodejs-private/node-private#890](https://github.com/nodejs-private/node-private/pull/890)
- \[[`a8a0d12875`](nodejs/node@a8a0d12875)] - **(CVE-2026-48937)** **deps**: fix integration issues with the latest nghttp2 (Tim Perry) [#&#8203;62891](nodejs/node#62891)
- \[[`66e6203c1c`](nodejs/node@66e6203c1c)] - **(SEMVER-MAJOR)** **deps**: update nghttp2 to 1.69.0 (Node.js GitHub Bot) [#&#8203;62891](nodejs/node#62891)
- \[[`dd627ced27`](nodejs/node@dd627ced27)] - **deps**: update archs files for openssl-3.5.7 (Node.js GitHub Bot) [#&#8203;63820](nodejs/node#63820)
- \[[`684bae568f`](nodejs/node@684bae568f)] - **deps**: upgrade openssl sources to openssl-3.5.7 (Node.js GitHub Bot) [#&#8203;63820](nodejs/node#63820)
- \[[`3a631e7f83`](nodejs/node@3a631e7f83)] - **deps**: fix aix implicit declaration in OpenSSL (Abdirahim Musse) [#&#8203;62656](nodejs/node#62656)
- \[[`cf44df3996`](nodejs/node@cf44df3996)] - **deps**: update undici to 7.28.0 (Node.js GitHub Bot) [#&#8203;63703](nodejs/node#63703)
- \[[`138c70294b`](nodejs/node@138c70294b)] - **(CVE-2026-48930)** **dns,net**: reject hostnames with embedded NUL bytes (Matteo Collina) [nodejs-private/node-private#868](https://github.com/nodejs-private/node-private/pull/868)
- \[[`be7e719c3f`](nodejs/node@be7e719c3f)] - **(CVE-2026-48931)** **http**: fix response queue poisoning in http.Agent (Matteo Collina) [nodejs-private/node-private#846](https://github.com/nodejs-private/node-private/pull/846)
- \[[`cc7c11b4d1`](nodejs/node@cc7c11b4d1)] - **(CVE-2026-48619)** **http2**: cap originSet size to prevent unbounded memory growth (Matteo Collina) [nodejs-private/node-private#855](https://github.com/nodejs-private/node-private/pull/855)
- \[[`9224427b92`](nodejs/node@9224427b92)] - **(CVE-2026-48615)** **lib,test**: redact proxy credentials in tunnel errors (Matteo Collina) [nodejs-private/node-private#867](https://github.com/nodejs-private/node-private/pull/867)
- \[[`cf85d54839`](nodejs/node@cf85d54839)] - **(CVE-2026-48935)** **permission**: disable FileHandle utimes with permission model (RafaelGSS) [nodejs-private/node-private#873](https://github.com/nodejs-private/node-private/pull/873)
- \[[`a1bbc24f96`](nodejs/node@a1bbc24f96)] - **(CVE-2026-48617)** **permission**: handle process.chdir on writereport (RafaelGSS) [nodejs-private/node-private#870](https://github.com/nodejs-private/node-private/pull/870)
- \[[`e3723ff2d6`](nodejs/node@e3723ff2d6)] - **test**: add session reuse host verification regressions (Matteo Collina) [nodejs-private/node-private#854](https://github.com/nodejs-private/node-private/pull/854)
- \[[`a77af4867b`](nodejs/node@a77af4867b)] - **(CVE-2026-48934)** **tls**: bind reusable sessions to authenticated host (Matteo Collina) [nodejs-private/node-private#854](https://github.com/nodejs-private/node-private/pull/854)
- \[[`31beb4f707`](nodejs/node@31beb4f707)] - **(CVE-2026-48928)** **tls**: fix case-sensitive SNI context matching (Matteo Collina) [nodejs-private/node-private#857](https://github.com/nodejs-private/node-private/pull/857)
- \[[`8e75c73f91`](nodejs/node@8e75c73f91)] - **(CVE-2026-48618)** **tls**: normalize hostname for server identity checks (Matteo Collina) [nodejs-private/node-private#869](https://github.com/nodejs-private/node-private/pull/869)
</details>
---
### Configuration
📅 **Schedule**: (UTC)
- Branch creation
- At any time (no schedule defined)
- Automerge
- At any time (no schedule defined)
🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.
♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 **Ignore**: Close this PR and you won't be reminded about this update again.
---
- [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box
---
This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzAuMTkiLCJ1cGRhdGVkSW5WZXIiOiI0My4xNzAuMTkiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbXX0=-->
Reviewed-on: https://git.walbeck.it/mwalbeck/docker-cyberchef/pulls/488
juanarbol pushed a commit to juanarbol/node that referenced this pull request Jul 16, 2026
Signed-off-by: Tim Perry <pimterry@gmail.com>
PR-URL: nodejs#63155
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>
Reviewed-By: Ethan Arrowood <ethan@arrowood.dev>
juanarbol added a commit that referenced this pull request Jul 16, 2026
Notable changes:
async_hooks:
* (SEMVER-MINOR) add trackPromises option to createHook() (Joyee Cheung) #61415
buffer:
* (SEMVER-MINOR) increase Buffer.poolSize default to 64 KiB (Matteo Collina) #63597
cli:
* (SEMVER-MINOR) add --max-heap-size option (tannal) #58708
console:
* (SEMVER-MINOR) allow per-stream `inspectOptions` option (Anna Henningsen) #60082
crypto:
* update root certificates to NSS 3.123.1 (Node.js GitHub Bot) #63527
debugger:
* (SEMVER-MINOR) add edit-free runtime expression probes to `node inspect` (Joyee Cheung) #62713
fs:
* (SEMVER-MINOR) add signal option to fs.stat() (Mert Can Altin) #57775
* (SEMVER-MINOR) expose frsize field in statfs (Jinho Jang) #62277
* (SEMVER-MINOR) add `throwIfNoEntry` option for fs.stat and fs.promises.stat (Juan José) #61178
* (SEMVER-MINOR) add ignore option to fs.watch (Matteo Collina) #61433
http:
* (SEMVER-MINOR) add writeInformation to send arbitrary 1xx status codes (Tim Perry) #63155
* (SEMVER-MINOR) add req.signal to IncomingMessage (Akshat) #62541
lib:
* (SEMVER-MINOR) remove util.getCallSite (Rafael Gonzaga) #59980
net:
* (SEMVER-MINOR) add `setTOS` and `getTOS` to `Socket` (Amol Yadav) #61503
node-api:
* (SEMVER-MINOR) support SharedArrayBuffer in napi_create_dataview (Kevin Eady) #60473
* (SEMVER-MINOR) add napi_create_object_with_properties (Miguel Marcondes Filho) #59953
perf_hooks:
* (SEMVER-MINOR) move non-standard performance properties to perf_hooks (Chengzhong Wu) #60370
sqlite:
* (SEMVER-MINOR) add sqlite prepare options args (Guilherme Araújo) #61311
* (SEMVER-MINOR) create authorization api (Guilherme Araújo) #59928
src:
* (CVE-2026-21712) handle url crash on different url formats (RafaelGSS) nodejs-private/node-private#816
src,permission:
* (SEMVER-MINOR) add --allow-inspector ability (Rafael Gonzaga) #59711
stream:
* (SEMVER-MINOR) add bytes() method to stream/consumers (wantaek) #60426
* (SEMVER-MINOR) do not pass `readable.compose()` output via `Readable.from()` (René) #60907
test_runner:
* (SEMVER-MINOR) align mock timeout api (sangwook) #62820
PR-URL: TODO
@juanarboljuanarbol mentioned this pull request Jul 16, 2026
jylenhof pushed a commit to jylenhof/mise-update-tool that referenced this pull request Aug 4, 2026
Automated mise tool upgrades from local config.
Updated tools:
- `action-validator`
- `actionlint`
- `aube`
- `editorconfig-checker`
- `ghalint`
- `node`
- `pinact`
- `pipx:gh-action-pulse`
- `prek`
- `rumdl`
- `shellcheck`
- `shfmt`
- `tombi`
- `uv`
- `yamlfmt`
- `yamllint`
- `zizmor`
Command: `mise upgrade --bump --local action-validator actionlint aube editorconfig-checker ghalint node pinact pipx:gh-action-pulse prek rumdl shellcheck shfmt tombi uv yamlfmt yamllint zizmor`
<details>
<summary>Version changelog (node)</summary>
| Tool | Requested | Installed |
|------|-----------|-----------|
| `node` | `24` → `26` | `24.18.1` → `26.5.1` |
</details>
<details>
<summary>Release notes (1 tools)</summary>
<details>
<summary>node: `24.18.1` → `26.5.1` (nodejs/node)</summary>
### v25.8.2
This is a security release.
### Notable Changes
* (CVE-2026-21637) wrap `SNICallback` invocation in `try`/`catch` (Matteo Collina) - High
* (CVE-2026-21710) use null prototype for `headersDistinct`/`trailersDistinct` (Matteo Collina) - High
* (CVE-2026-21711) include permission check to `pipe_wrap.cc` (RafaelGSS) - Medium
* (CVE-2026-21712) handle url crash on different url formats (RafaelGSS) - Medium
* (CVE-2026-21713) use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) - Medium
* (CVE-2026-21714) handle `NGHTTP2_ERR_FLOW_CONTROL` error code (RafaelGSS) - Medium
* (CVE-2026-21717) test array index hash collision (Joyee Cheung) - Medium
* (CVE-2026-21715) add permission check to `realpath.native` (RafaelGSS) - Low
* (CVE-2026-21716) include permission check on `lib/fs/promises` (RafaelGSS) - Low
### Commits
* \[[`2086b7477b`](nodejs/node@2086b7477b)] - **(CVE-2026-21717)** **build,test**: test array index hash collision (Joyee Cheung) [nodejs-private/node-private#834](https://github.com/nodejs-private/node-private/pull/834)
* \[[`0f9332a40a`](nodejs/node@0f9332a40a)] - **(CVE-2026-21713)** **crypto**: use timing-safe comparison in Web Cryptography HMAC and KMAC (Filip Skokan) [nodejs-private/node-private#822](https://github.com/nodejs-private/node-private/pull/822)
* \[[`2b6937ddb2`](nodejs/node@2b6937ddb2)] - **deps**: update undici to 7.24.4 (Node.js GitHub Bot) [#62271](nodejs/node#62271)
* \[[`bfb8ad5787`](nodejs/node@bfb8ad5787)] - **deps**: update undici to 7.24.3 (Node.js GitHub Bot) [#62233](nodejs/node#62233)
* \[[`be6384727f`](nodejs/node@be6384727f)] - **deps**: upgrade npm to 11.11.1 (npm team) [#62216](nodejs/node#62216)
* \[[`2feea5bb97`](nodejs/node@2feea5bb97)] - **deps**: V8: override… (truncated)
### v25.9.0
### Notable Changes
#### Test runner module mocking improvements
`MockModuleOptions.defaultExport` and `MockModuleOptions.namedExports` have been
consolidated into a single option `MockModuleOptions.exports` to align with user
expectations and other test runners.
A `default` property on `MockModuleOptions.exports` represents the default
export, and own enumerable properties are treated as named exports.
An automated migration is available to update user code:
<https://github.com/nodejs/userland-migrations/tree/main/recipes/mock-module-exports>
```bash
npx codemod @​nodejs/mock-module-exports
```
Contributed by sangwook in [#61727](nodejs/node#61727).
#### Other notable changes
* \[[`312476cb84`](nodejs/node@312476cb84)] - **(SEMVER-MINOR)** **async\_hooks**: add using scopes to `AsyncLocalStorage` (Stephen Belanger) [#61674](nodejs/node#61674)
* \[[`62d2cd473b`](nodejs/node@62d2cd473b)] - **(SEMVER-MINOR)** **cli**: add `--max-heap-size` option (tannal) [#58708](nodejs/node#58708)
* \[[`d0ebf0e44b`](nodejs/node@d0ebf0e44b)] - **(SEMVER-MINOR)** **crypto**: add `TurboSHAKE` and `KangarooTwelve` Web Cryptography algorithms (Filip Skokan) [#62183](nodejs/node#62183)
* \[[`f85b9d9fa8`](nodejs/node@f85b9d9fa8)] - **(SEMVER-MINOR)** **repl**: add customizable error handling (Anna Henningsen) [#62188](nodejs/node#62188)
* \[[`67b854d407`](nodejs/node@67b854d407)] - **(SEMVER-MINOR)** **repl**: remove dependency on `node:domain` (Matteo Collina) [#61227](nodejs/node#61227)
* \[[`966b700623`](nodejs/node@966b700623)] - **(SEMVER-MINOR)** **sea**: support code cache for ESM entrypoint in SEA (Joyee Cheung) [#62158](nodejs/node#62158)
*… (truncated)
### v26.0.0
We're excited to announce the release of Node.js 26! Highlights include the Temporal API enabled by default,
updates to the V8 JavaScript engine to 14.6, Undici to 8.0, and several important deprecations and removals
as we continue to modernize the platform.
As a reminder, Node.js 26 will enter long-term support (LTS) in October, but until then, it will be the "Current" release for the next six months.
We encourage you to explore the new features and benefits offered by this latest release and evaluate their potential impact on your applications.
### Notable Changes
#### Temporal API
The Temporal API is now enabled by default in Node.js 26. Temporal is a modern date/time API for JavaScript
that provides a more robust and feature-rich alternative to the legacy `Date` object.
Contributed by Richard Lau in [#61806](nodejs/node#61806).
#### V8 14.6
The V8 engine is updated to version 14.6.202.33, which is part of Chromium 134.
This version also includes:
* Upsert (<https://github.com/tc39/proposal-upsert>): `[Weak]Map.prototype.getOrInsert()`, `[Weak]Map.prototype.getOrInsertComputed()`
* Iterator sequencing (<https://github.com/tc39/proposal-iterator-sequencing>): `Iterator.concat()`
Contributed by Michaël Zasso in [#61898](nodejs/node#61898).
#### Undici 8
Undici has been updated to version 8.0.2, bringing new features and improvements to Node.js's HTTP client implementation.
#### Deprecations and Removals
* \[[`dff46c07c3`](nodejs/node@dff46c07c3)] - **(SEMVER-MAJOR)** **crypto**: move DEP0182 to End-of-Life (Tobias Nießen) [#61084](nodejs/node#61084)
* \[[`93c25815ee`](nodejs/node@93c25815ee)] - **(SEMVER-MAJOR)** **http**: move writeHeader to end-of-life (Sebastian Beltran) [#60635](nodejs/node#60635)
`http.Server.prototype.writeHeader()` is now fully removed. Use `http.Server.prototype.write… (truncated)
### v26.1.0
### Notable Changes
#### Experimental `node:ffi` module
Node.js now includes an experimental `node:ffi` module for loading dynamic
libraries and calling native symbols from JavaScript.
The API is gated behind the `--experimental-ffi` flag and, when the Permission
Model is enabled, requires `--allow-ffi`.
This API is inherently unsafe. Invalid pointers, incorrect signatures, or accessing memory
after it has been freed can crash the process or corrupt memory.
Contributed by Paolo Insogna in [#62072](nodejs/node#62072).
#### Other Notable Changes
* \[[`34a6454fe3`](nodejs/node@34a6454fe3)] - **(SEMVER-MINOR)** **buffer**: add `end` parameter (Robert Nagy) [#62390](nodejs/node#62390)
* \[[`073e84d7fe`](nodejs/node@073e84d7fe)] - **(SEMVER-MINOR)** **crypto**: accept key data in `crypto.diffieHellman()` and cleanup DH jobs (Filip Skokan) [#62527](nodejs/node#62527)
* \[[`5b9cb10a5f`](nodejs/node@5b9cb10a5f)] - **(SEMVER-MINOR)** **crypto**: implement `randomUUIDv7()` (nabeel378) [#62553](nodejs/node#62553)
* \[[`98f9becd16`](nodejs/node@98f9becd16)] - **(SEMVER-MINOR)** **debugger**: add edit-free runtime expression probes to `node inspect` (Joyee Cheung) [#62713](nodejs/node#62713)
* \[[`06defaa2ea`](nodejs/node@06defaa2ea)] - **(SEMVER-MINOR)** **fs**: add `signal` option to `fs.stat()` (Mert Can Altin) [#57775](nodejs/node#57775)
* \[[`db66a963bf`](nodejs/node@db66a963bf)] - **(SEMVER-MINOR)** **fs**: expose `frsize` field in `statfs` (Jinho Jang) [#62277](nodejs/node#62277)
* \[[`87adb3472b`](nodejs/node@87adb3472b)] - **(SEMVER-MINOR)** **http**: harden `ClientRequest` options merge (Matteo Collina) [#6… (truncated)
### v26.2.0
### Notable Changes
* \[[`189d43a193`](nodejs/node@189d43a193)] - **doc**: mark `stream.compose` stable (Matteo Collina) [#62562](nodejs/node#62562)
* \[[`f858c6140e`](nodejs/node@f858c6140e)] - **(SEMVER-MINOR)** **fs**: add `Temporal.Instant` support to `Stats` and `BigIntStats` (Livia Medeiros) [#60789](nodejs/node#60789)
* \[[`0cbb3895df`](nodejs/node@0cbb3895df)] - **(SEMVER-MINOR)** **http**: add `writeInformation` to send arbitrary 1xx status codes (Tim Perry) [#63155](nodejs/node#63155)
### Commits
* \[[`9a394bab84`](nodejs/node@9a394bab84)] - **benchmark**: respect stream/iter broadcast backpressure (Trivikram Kamat) [#63314](nodejs/node#63314)
* \[[`ad98b4620b`](nodejs/node@ad98b4620b)] - **crypto**: align verifyOneShot accepted types (Anshika Jain) [#63280](nodejs/node#63280)
* \[[`ba0736a847`](nodejs/node@ba0736a847)] - **crypto**: wire ML-DSA and ML-KEM for use when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255)
* \[[`5573a6a4a8`](nodejs/node@5573a6a4a8)] - **crypto**: wire ChaCha20-Poly1305 in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255)
* \[[`7dc563b8d6`](nodejs/node@7dc563b8d6)] - **crypto**: wire AES-KW in Web Cryptography when using BoringSSL (Filip Skokan) [#63255](nodejs/node#63255)
* \[[`b55e2b1f4d`](nodejs/node@b55e2b1f4d)] - **crypto**: improve system certificate enumeration logic on macOS (Robo) [#62576](nodejs/node#62576)
* \[[`fd509a755a`](nodejs/node@fd509a755a)] - **crypto**: harden CryptoKey algorithm slots… (truncated)
### v26.3.0
### Notable Changes
#### Potential changes to macOS Universal Binary availability
With Apple and its ecosystem progressively dropping support for Intel-based
architectures, it has become apparent that the Node.js project may not be able
to maintain the universal binaries we currently distribute for the full lifetime
of Node.js 26. This change serves to communicate that risk. At present, our
intention remains to continue shipping universal binaries supporting both Apple
Silicon and Intel-based Macs for as long as practical.
Contributed by Antoine du Hamel in [#63055](nodejs/node#63055).
#### Other notable changes
* \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase `Buffer.poolSize` default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597)
* \[[`051a2152f7`](nodejs/node@051a2152f7)] - **crypto**: update root certificates to NSS 3.123.1 (Node.js GitHub Bot) [#63527](nodejs/node#63527)
* \[[`49462eca37`](nodejs/node@49462eca37)] - **(SEMVER-MINOR)** **http**: add `httpValidation` option to configure header value validation (RajeshKumar11) [#61597](nodejs/node#61597)
* \[[`97b7ab19bd`](nodejs/node@97b7ab19bd)] - **(SEMVER-MINOR)** **inspector**: expose precise coverage start to JS runtime (sangwook) [#63079](nodejs/node#63079)
* \[[`cfb80a2103`](nodejs/node@cfb80a2103)] - **(SEMVER-MINOR)** **lib,permission**: add `permission.drop` (Rafael Gonzaga) [#62672](nodejs/node#62672)
### Commits
* \[[`a2a4b33dd8`](nodejs/node@a2a4b33dd8)] - **(SEMVER-MINOR)** **buffer**: increase Buffer.poolSize default to 64 KiB (Matteo Collina) [#63597](nodejs/node#63597)
* \[[`0eff3e23b9`](https://github.com/nodejs/n… (truncated)
### v26.3.1
This is a security release.
### Notable Changes
* (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
* (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
* (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
* (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
* (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
* (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
* (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
* (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
* (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
* (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
* (CVE-2026-48936) permission: guard pipe open and chmod with net scope (RafaelGSS) – Low
### Commits
* \[[`98fbc89211`](nodejs/node@98fbc89211)] - **(CVE-2026-48933)** **crypto**: guard WebCrypto cipher output length (Filip Skokan) [nodejs-private/node-private#878](https://github.com/nodejs-private/node-private/pull/878)
* \[[`110840f2c7`](nodejs/node@110840f2c7)] - **deps**: update llhttp to 9.4.2 (Antoine du Hamel) [nodejs-private/node-private#890](https://github.com/nodejs-private/node-private/pull/890)
* \[[`8d36d522b2`](nodejs/node@8d36d522b2)] - **deps**: update undici to 8.5.0 (Node.js GitHub Bot) [#63903](nodejs/node#63903)
* \[[`2e6d03993a`](nodejs/node@2e6d03993a)] - **deps**: update undici to 8.4.0 (Node.js GitHub Bot) [#63779](nodejs/node#63779)
* \[[`5a17d5b07a`](nodejs/node@5a17d5b07a)] - **deps… (truncated)
### v26.4.0
### Notable Changes
* \[[`cde0daabcc`](nodejs/node@cde0daabcc)] - **(SEMVER-MINOR)** **doc**: update `blockList` stability status to release candidate (alphaleadership) [#63050](nodejs/node#63050)
* \[[`b78f5a7537`](nodejs/node@b78f5a7537)] - **(SEMVER-MINOR)** **fs**: support caller-supplied `readFile()` buffers (Matteo Collina) [#63634](nodejs/node#63634)
* \[[`417aacbc36`](nodejs/node@417aacbc36)] - **(SEMVER-MINOR)** **http**: close pre-request sockets in `closeIdleConnections` (semimikoh) [#63470](nodejs/node#63470)
* \[[`fbb108be7d`](nodejs/node@fbb108be7d)] - **(SEMVER-MINOR)** **loader**: implement package maps (Maël Nison) [#62239](nodejs/node#62239)
* \[[`45494d5a8a`](nodejs/node@45494d5a8a)] - **(SEMVER-MINOR)** **net**: support `TCP_KEEPINTVL` and `TCP_KEEPCNT` in `setKeepAlive` (Guy Bedford) [#63825](nodejs/node#63825)
* \[[`ee29465e77`](nodejs/node@ee29465e77)] - **(SEMVER-MINOR)** **tls**: add certificateCompression option (Tim Perry) [#62217](nodejs/node#62217)
* \[[`b17817eb2b`](nodejs/node@b17817eb2b)] - **(SEMVER-MINOR)** **vfs**: dispatch `node:fs/promises` to mounted VFS instances (Matteo Collina) [#63537](nodejs/node#63537)
* \[[`7bc93a6ac5`](nodejs/node@7bc93a6ac5)] - **(SEMVER-MINOR)** **vfs**: add minimal `node:vfs` subsystem (Matteo Collina) [#63115](nodejs/node#63115)
### Commits
* \[[`c7eb83b46a`](nodejs/node@c7eb83b46a)] - **benchmark**: add child\_process async path baselines (Yagiz Nizipli) [#63929](nodejs/node#63929)
* \[[`066fff17a5`](https://github.com/nodejs/node/commit/066f… (truncated)
### v26.5.0
### Notable Changes
#### New release key
Welcome to our newest releaser, [Stewart X Addison](https://github.com/sxa). Future Node.js releases may be signed with his [release key](https://github.com/nodejs/node/blob/main/README.md#release-keys), `655F3B5C1FB3FA8D1A0CA6BDE4A7D232B936D2FD`.
#### Other notable changes
* \[[`55f48446c7`](nodejs/node@55f48446c7)] - **(SEMVER-MINOR)** **buffer**: implement blob.textStream() (Matthew Aitken) [#64036](nodejs/node#64036)
* \[[`b373202efc`](nodejs/node@b373202efc)] - **(SEMVER-MINOR)** **esm**: add `--experimental-import-text` flag (Efe) [#62300](nodejs/node#62300)
* \[[`39e0c14455`](nodejs/node@39e0c14455)] - **(SEMVER-MINOR)** **perf\_hooks**: sample delay per event loop iteration (Pablo Erhard) [#62935](nodejs/node#62935)
* \[[`999a83c937`](nodejs/node@999a83c937)] - **(SEMVER-MINOR)** **stream**: expose ReadableStreamTee (Matteo Collina) [#64195](nodejs/node#64195)
* \[[`4e0236dc3d`](nodejs/node@4e0236dc3d)] - **(SEMVER-MINOR)** **tls**: report negotiated TLS groups (Filip Skokan) [#64119](nodejs/node#64119)
### Commits
* \[[`87648c0a6c`](nodejs/node@87648c0a6c)] - **benchmark**: trim down the argon2 sets (Filip Skokan) [#64218](nodejs/node#64218)
* \[[`a483bfd3f0`](nodejs/node@a483bfd3f0)] - **buffer**: remove unreachable overflow check in atob (haramjeong) [#60161](nodejs/node#60161)
* \[[`6d14279688`](nodejs/node@6d14279688)] - **buffer**: add fast api for isUtf8 and isAscii (Gürgün Dayıoğlu) [#64169](nodejs/node#64169)
* \[[`55f48446c7`](nodejs/node@55f48446c7)] -… (truncated)
### v26.5.1
This is a security release.
### Notable Changes
* (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
* (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
* (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
* (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
* (CVE-2026-58041) sqlite: invalidate tag store iterators on statement reset (Matteo Collina) – Medium
* (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
* (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
* (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
* (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
* (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
* deps: update llhttp to 9.4.3 (Paolo Insogna)
* deps: update undici to 8.9.0 (Node.js GitHub Bot)
### Commits
* \[[`af0bf96877`](nodejs/node@af0bf96877)] - **deps**: update llhttp to 9.4.3 (Paolo Insogna) [nodejs-private/node-private#935](https://github.com/nodejs-private/node-private/pull/935)
* \[[`0354678355`](nodejs/node@0354678355)] - **deps**: update undici to 8.9.0 (Node.js GitHub Bot) [#64712](nodejs/node#64712)
* \[[`dbeeaeec13`](nodejs/node@dbeeaeec13)] - **(CVE-2026-58042)** **dns**: handle large resolveAny address replies (RafaelGSS) [nodejs-private/node-private#929](https://github.com/nodejs-private/node-private/pull/929)
* \[[`064d339f56`](nodejs/node@064d339f56)] - **(CVE-2026-58044)** **http**: reject requests exceeding max header count (Matteo Collina) [nodejs-private/node-private#922](https://github.com/nodejs-private/node-private/pull/922)
* \[[`23b94c843a`](https://github.… (truncated)
_Omitted 12 older releases._
</details>
</details>
Modified files:
- `.mise.toml`
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

httpIssues or PRs related to the http subsystem.http2Issues or PRs related to the http2 subsystem.needs-ciPRs that need a full CI run.semver-minorPRs that contain new features and should be released in the next minor version.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants

@pimterry@nodejs-github-bot@mcollina@jasnell@metcoder95@Ethan-Arrowood