What’s New

Node.js v24.17.0

v24.17.0

2026-06-18, Version 24.17.0 'Krypton' (LTS), @aduh95

Security
  • Normalize hostname for server identity checks in tls
  • Guard WebCrypto cipher output length in crypto
  • Redact proxy credentials in tunnel errors
  • Cap originSet size in http2 to prevent unbounded memory growth
  • Fix case-sensitive SNI context matching in tls
  • Reject hostnames with embedded NUL bytes in dns and net
  • Bind reusable sessions to authenticated host in tls
  • Fix integration issues with the latest nghttp2
  • Handle process.chdir on writereport in permission
  • Fix response queue poisoning in http.Agent
  • Disable FileHandle utimes with permission model

This is a security release.

Notable Changes
  • (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
  • (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
  • (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
  • (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
  • (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
  • (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
  • (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
  • (CVE-2026-48937) deps: fix integration issues with the latest nghttp2 – Medium
  • (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
  • (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
  • (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
Commits
View original