Back to blog

// OSSeva Blog

Security

Who Provides Node.js Security Patches After End of Life? (Node 18 and 20)

Matt Reynolds9 min read

The short answer

Four providers publish security patches for Node.js 18 and 20 after the Node.js project stopped: HeroDevs (Never-Ending Support, Node.js 12 to 20), TuxCare (Endless Lifecycle Support, Node.js 12 to 20), OSSeva (patched Node.js 14 to 20 runtimes, with V8 and libuv fixes included) and Canonical (Ubuntu Pro, for the nodejs package that Ubuntu itself ships). The Node.js project's own end-of-life page points to HeroDevs and TuxCare through the OpenJS Foundation's Ecosystem Sustainability Program.

The project ended Node.js 18 on 30 April 2025 and Node.js 20 on 30 April 2026. Upgrading to Node.js 22 or 24 remains the long-term answer; paid support is how you stay patched while that happens.

Node.js end-of-life dates

LineCodenameEnd of lifeStatus on 6 October 2026
Node.js 16Gallium11 September 2023No upstream fixes
Node.js 18Hydrogen30 April 2025No upstream fixes; last release 18.20.8
Node.js 20Iron30 April 2026No upstream fixes; last release 20.20.2
Node.js 22Jod30 April 2027Maintenance LTS: security and critical fixes
Node.js 24Krypton30 April 2028LTS

Dates are from the Node.js release schedule. Once a line ends, new advisories in Node.js security releases name only the supported lines, so a scanner may stay quiet about Node.js 18 or 20 while the vulnerable code is still there. Our Node.js vulnerabilities by version lists the CVEs published since each line ended.

Node.js end-of-life support providers compared

Each row reflects what the vendor publishes on its own site as of 6 October 2026.

ProviderWhat it coversVersionsDelivery modelSelf-managed?
HeroDevs Never-Ending SupportSecurity fixes backported to end-of-life Node.js, SLA-backed by severity, with compliance support for frameworks such as SOC 2, PCI DSS, HIPAA and FedRAMP12, 14, 16, 18 and 20Container images and binaries, as a drop-in replacement; AWS, Azure, Google Cloud and on premisesYes
TuxCare Endless Lifecycle SupportBackported, tested and signed security patches, SLA-backed, with SBOM and VEX documentation12, 14, 16, 18 and 20; TuxCare says 22 will be added when it reaches end of lifeThrough npm and your existing package managers and build toolsYes
OSSevaQuarterly CVE patches for the Node.js runtime, with V8 engine and libuv fixes included; upgrade planning and 24/7 operations on higher tiers14, 16, 18 and 20GPG-signed Docker images (Alpine and Debian), apt and yum packages, and binariesYes
Canonical (Ubuntu Pro)Security maintenance for the nodejs package in Ubuntu's universe component through ESM AppsThe version each Ubuntu release ships (18.19.1 on Ubuntu 24.04 LTS)APT packages on UbuntuYes, on Ubuntu

Canonical's coverage follows the Ubuntu package, not the upstream line. If your services run the official Node.js tarballs or Docker images rather than Ubuntu's package, Ubuntu Pro does not patch them. NodeSource, which the Node.js site also lists, sells an upgrade programme rather than patched runtimes for these lines; its extended support page names Node.js 12 and 14 and does not list 18 or 20, so it is not in the table.

How the providers differ

HeroDevs

HeroDevs has the longest published list of end-of-life JavaScript frameworks of any vendor, so it fits estates where Node.js sits next to AngularJS, Vue 2 or old Express and Next.js versions. Its Node.js product ships container images and binaries, and it lists coverage across serverless functions, Kubernetes and virtual machines. Our OSSeva vs HeroDevs comparison goes into the overlap.

TuxCare

TuxCare delivers through the package managers you already use and ships SBOM and VEX documents with each release, which suits teams that already buy its operating-system or library coverage. It also covers Python, PHP, Java, Ruby and .NET runtimes. See OSSeva vs TuxCare.

OSSeva

OSSeva for Node.js ships patched runtimes for Node.js 14, 16, 18 and 20. V8 and libuv vulnerabilities are assessed against each covered line and backported into the Node.js build, so there is no separate engine contract. The images are drop-in replacements for Kubernetes manifests: you change the tag. The Assure tier adds transitive npm dependency scanning, HTTP/2 and TLS configuration review and upgrade path planning; Operate adds 24/7 monitoring, PM2 and cluster-mode support, and runs the major-version migration with you.

Canonical

If your Node.js comes from Ubuntu's own nodejs package, Ubuntu Pro is the simplest option: fixes arrive through apt. On Ubuntu 24.04 LTS that package is Node.js 18. It does nothing for Node.js installed from other sources.

Should you upgrade Node.js or use extended support?

Upgrade when you can; buy support for the services you cannot move in time. Most teams end up doing both, service by service. These questions sort each service into one column:

QuestionPoints to upgrading nowPoints to extended support first
How many services run the old line?A handful, with active ownersDozens, or some with no clear owner
Do native addons or pinned packages block the move?No, npm ci and tests pass on 22 or 24Yes, addons need rebuilding or dependencies have no compatible release
Is the service changing anyway?Yes, it is under active developmentNo, it is stable or due for retirement
Is an audit or customer questionnaire coming?The upgrade can land firstEvidence of a supported runtime is needed before the upgrade can
Is the service exposed to the internet?Either way, exposure makes the open advisories urgentPatch now if the upgrade will take more than a release cycle

For Node.js 20, the jump to 22 is small for most code. For Node.js 18 or 16, the breaking changes accumulate, and the slowest dependency usually sets the date. Our Node.js 18 or 20 to 22 or 24 upgrade guide lists the breaking changes, steps and rollback.

If you buy support, treat it as a dated plan rather than a destination. The Node.js project describes commercial support for end-of-life lines as a temporary solution, with upgrading as the goal. Record the upgrade date for each service in your end-of-life inventory, and check that the contract covers the line you will be on until then. Node.js 22 itself ends on 30 April 2027.

Where OSSeva fits

OSSeva patches the Node.js runtime itself, including V8 and libuv, for Node.js 14 to 20, delivered as signed images and packages through your existing registries. Teams with brokers, databases or ZooKeeper on old versions can cover those under the same contract. The extended support vendor roundup compares OSSeva, HeroDevs, TuxCare and others by technology layer.

Frequently asked questions

Who provides security patches for Node.js 18 and 20 after end of life?

HeroDevs (Never-Ending Support), TuxCare (Endless Lifecycle Support) and OSSeva all publish patched builds for Node.js 18 and 20. Canonical patches the Node.js package that Ubuntu ships, which is Node.js 18 on Ubuntu 24.04 LTS.

Compare Node.js end-of-life support companies: how are they different?

HeroDevs pairs Node.js with the widest list of end-of-life JavaScript frameworks. TuxCare delivers through your package managers with SBOM and VEX data and covers many other runtimes. OSSeva includes V8 and libuv fixes in its Node.js builds and can also run the service 24/7 alongside brokers and databases. Canonical covers only Ubuntu's own package.

Should we upgrade Node.js or use extended support?

Upgrade services that are under active development and have no blocking dependencies. Use extended support for the rest while they migrate, with a recorded upgrade date for each. Doing neither leaves new runtime advisories open.

Does Node.js 20 still get security updates?

Not from the Node.js project. Its last release was 20.20.2, and the line ended on 30 April 2026. Fixes for Node.js 20 now come only from commercial providers.

Is Node.js 22 safe to move to?

Yes, but it is already in maintenance and ends on 30 April 2027. Node.js 24, supported to 30 April 2028, gives a longer runway.

Tags

Node.jsEnd of LifeExtended SupportVendor ComparisonPatching

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.