// OSSeva Blog
SecurityWho Provides Node.js Security Patches After End of Life? (Node 18 and 20)
The short answer
Four providers publish security patches for Node.js 18 and 20 after the Node.js project stopped: HeroDevs (Never-Ending Support, Node.js 12 to 20), TuxCare (Endless Lifecycle Support, Node.js 12 to 20), OSSeva (patched Node.js 14 to 20 runtimes, with V8 and libuv fixes included) and Canonical (Ubuntu Pro, for the nodejs package that Ubuntu itself ships). The Node.js project's own end-of-life page points to HeroDevs and TuxCare through the OpenJS Foundation's Ecosystem Sustainability Program.
The project ended Node.js 18 on 30 April 2025 and Node.js 20 on 30 April 2026. Upgrading to Node.js 22 or 24 remains the long-term answer; paid support is how you stay patched while that happens.
Node.js end-of-life dates
| Line | Codename | End of life | Status on 6 October 2026 |
|---|---|---|---|
| Node.js 16 | Gallium | 11 September 2023 | No upstream fixes |
| Node.js 18 | Hydrogen | 30 April 2025 | No upstream fixes; last release 18.20.8 |
| Node.js 20 | Iron | 30 April 2026 | No upstream fixes; last release 20.20.2 |
| Node.js 22 | Jod | 30 April 2027 | Maintenance LTS: security and critical fixes |
| Node.js 24 | Krypton | 30 April 2028 | LTS |
Dates are from the Node.js release schedule. Once a line ends, new advisories in Node.js security releases name only the supported lines, so a scanner may stay quiet about Node.js 18 or 20 while the vulnerable code is still there. Our Node.js vulnerabilities by version lists the CVEs published since each line ended.
Node.js end-of-life support providers compared
Each row reflects what the vendor publishes on its own site as of 6 October 2026.
| Provider | What it covers | Versions | Delivery model | Self-managed? |
|---|---|---|---|---|
| HeroDevs Never-Ending Support | Security fixes backported to end-of-life Node.js, SLA-backed by severity, with compliance support for frameworks such as SOC 2, PCI DSS, HIPAA and FedRAMP | 12, 14, 16, 18 and 20 | Container images and binaries, as a drop-in replacement; AWS, Azure, Google Cloud and on premises | Yes |
| TuxCare Endless Lifecycle Support | Backported, tested and signed security patches, SLA-backed, with SBOM and VEX documentation | 12, 14, 16, 18 and 20; TuxCare says 22 will be added when it reaches end of life | Through npm and your existing package managers and build tools | Yes |
| OSSeva | Quarterly CVE patches for the Node.js runtime, with V8 engine and libuv fixes included; upgrade planning and 24/7 operations on higher tiers | 14, 16, 18 and 20 | GPG-signed Docker images (Alpine and Debian), apt and yum packages, and binaries | Yes |
| Canonical (Ubuntu Pro) | Security maintenance for the nodejs package in Ubuntu's universe component through ESM Apps | The version each Ubuntu release ships (18.19.1 on Ubuntu 24.04 LTS) | APT packages on Ubuntu | Yes, on Ubuntu |
Canonical's coverage follows the Ubuntu package, not the upstream line. If your services run the official Node.js tarballs or Docker images rather than Ubuntu's package, Ubuntu Pro does not patch them. NodeSource, which the Node.js site also lists, sells an upgrade programme rather than patched runtimes for these lines; its extended support page names Node.js 12 and 14 and does not list 18 or 20, so it is not in the table.
How the providers differ
HeroDevs
HeroDevs has the longest published list of end-of-life JavaScript frameworks of any vendor, so it fits estates where Node.js sits next to AngularJS, Vue 2 or old Express and Next.js versions. Its Node.js product ships container images and binaries, and it lists coverage across serverless functions, Kubernetes and virtual machines. Our OSSeva vs HeroDevs comparison goes into the overlap.
TuxCare
TuxCare delivers through the package managers you already use and ships SBOM and VEX documents with each release, which suits teams that already buy its operating-system or library coverage. It also covers Python, PHP, Java, Ruby and .NET runtimes. See OSSeva vs TuxCare.
OSSeva
OSSeva for Node.js ships patched runtimes for Node.js 14, 16, 18 and 20. V8 and libuv vulnerabilities are assessed against each covered line and backported into the Node.js build, so there is no separate engine contract. The images are drop-in replacements for Kubernetes manifests: you change the tag. The Assure tier adds transitive npm dependency scanning, HTTP/2 and TLS configuration review and upgrade path planning; Operate adds 24/7 monitoring, PM2 and cluster-mode support, and runs the major-version migration with you.
Canonical
If your Node.js comes from Ubuntu's own nodejs package, Ubuntu Pro is the simplest option: fixes arrive through apt. On Ubuntu 24.04 LTS that package is Node.js 18. It does nothing for Node.js installed from other sources.
Should you upgrade Node.js or use extended support?
Upgrade when you can; buy support for the services you cannot move in time. Most teams end up doing both, service by service. These questions sort each service into one column:
| Question | Points to upgrading now | Points to extended support first |
|---|---|---|
| How many services run the old line? | A handful, with active owners | Dozens, or some with no clear owner |
| Do native addons or pinned packages block the move? | No, npm ci and tests pass on 22 or 24 | Yes, addons need rebuilding or dependencies have no compatible release |
| Is the service changing anyway? | Yes, it is under active development | No, it is stable or due for retirement |
| Is an audit or customer questionnaire coming? | The upgrade can land first | Evidence of a supported runtime is needed before the upgrade can |
| Is the service exposed to the internet? | Either way, exposure makes the open advisories urgent | Patch now if the upgrade will take more than a release cycle |
For Node.js 20, the jump to 22 is small for most code. For Node.js 18 or 16, the breaking changes accumulate, and the slowest dependency usually sets the date. Our Node.js 18 or 20 to 22 or 24 upgrade guide lists the breaking changes, steps and rollback.
If you buy support, treat it as a dated plan rather than a destination. The Node.js project describes commercial support for end-of-life lines as a temporary solution, with upgrading as the goal. Record the upgrade date for each service in your end-of-life inventory, and check that the contract covers the line you will be on until then. Node.js 22 itself ends on 30 April 2027.
Where OSSeva fits
OSSeva patches the Node.js runtime itself, including V8 and libuv, for Node.js 14 to 20, delivered as signed images and packages through your existing registries. Teams with brokers, databases or ZooKeeper on old versions can cover those under the same contract. The extended support vendor roundup compares OSSeva, HeroDevs, TuxCare and others by technology layer.
Frequently asked questions
Who provides security patches for Node.js 18 and 20 after end of life?
HeroDevs (Never-Ending Support), TuxCare (Endless Lifecycle Support) and OSSeva all publish patched builds for Node.js 18 and 20. Canonical patches the Node.js package that Ubuntu ships, which is Node.js 18 on Ubuntu 24.04 LTS.
Compare Node.js end-of-life support companies: how are they different?
HeroDevs pairs Node.js with the widest list of end-of-life JavaScript frameworks. TuxCare delivers through your package managers with SBOM and VEX data and covers many other runtimes. OSSeva includes V8 and libuv fixes in its Node.js builds and can also run the service 24/7 alongside brokers and databases. Canonical covers only Ubuntu's own package.
Should we upgrade Node.js or use extended support?
Upgrade services that are under active development and have no blocking dependencies. Use extended support for the rest while they migrate, with a recorded upgrade date for each. Doing neither leaves new runtime advisories open.
Does Node.js 20 still get security updates?
Not from the Node.js project. Its last release was 20.20.2, and the line ended on 30 April 2026. Fixes for Node.js 20 now come only from commercial providers.
Is Node.js 22 safe to move to?
Yes, but it is already in maintenance and ends on 30 April 2027. Node.js 24, supported to 30 April 2028, gives a longer runway.
Tags
Related articles
Apache Storm Vulnerabilities by Version: CVEs for Storm 1.2, 2.x and 3.x
October 6, 2026Securityetcd Vulnerabilities by Version: CVEs for etcd 3.3, 3.4, 3.5, 3.6 and 3.7
October 6, 2026SecurityClickHouse Vulnerabilities by Version: CVEs for ClickHouse 22.x to 26.x, LTS and Stable
October 6, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.