← Back to Resources
Open Source NewsJuly 29, 20262 min read

Node.js July 2026 Security Releases

By BIOS Founding Team

Node.js July 2026 Security Releases

A coordinated security release across the 26.x, 24.x, and 22.x lines fixed 11 CVEs, including 3 HIGH-severity issues: an HTTP/2 flow-control bypass, an HTTP/2 re-entrant-send heap-use-after-free, and a Permission Model path-matching flaw that over-granted filesystem access.

It also patched several medium and low-severity issues in HTTPS Agent mTLS handling, node:sqlite, node:zlib, and DNS resolution, alongside undici and llhttp dependency bumps. If you run Node.js anywhere in production, releases like this are worth applying promptly.

Full details: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases