Back to blog

// OSSeva Blog

Security

Node.js Vulnerabilities by Version: CVEs for Node 18, 20, 22, 24 and 26

Randall McClure9 min read

The short answer

Three Node.js release lines get security fixes today: 22, 24 and 26. Node.js 22 is in Maintenance LTS until 30 April 2027. Node.js 24 is Active LTS until 20 October 2026, then in maintenance until 30 April 2028. Node.js 26 is the Current release, becomes LTS on 28 October 2026 and is supported until 30 April 2029. Node.js 20 reached end of life on 30 April 2026 and Node.js 18 on 30 April 2025. Every Node.js security release since those dates has patched the supported lines only. The last security release for Node.js 20 was 20.20.2 in March 2026, and for Node.js 18 it was 18.20.6 in January 2025.

How Node.js treats end-of-life lines

The Node.js project does not assess security reports against end-of-life lines, and each security release announcement says that end-of-life versions "are always affected". In January 2025 the project issued three CVEs that simply marked end-of-life versions as vulnerable (CVE-2025-23087, CVE-2025-23088 and CVE-2025-23089). The CVE Program rejected them. The project then said that new CVEs would include end-of-life releases in their applicability unless it had information showing a CVE does not apply.

You can see the effect in NVD. The version range for CVE-2026-21637 starts at 4.0.0, and the range for CVE-2026-21710 covers every release up to 20.20.1, so a scanner will flag Node.js 18 and 16 for both alongside unpatched 20.x.

Security releases since January 2025

ReleaseLines patchedCVEs rated High by Node.jsFixed versions
January 202518, 20, 22, 23CVE-2025-2308318.20.6, 20.18.2, 22.13.1, 23.6.1
May 202520, 22, 23, 24CVE-2025-2316620.19.2, 22.15.1, 23.11.1, 24.0.2
July 202520, 22, 24CVE-2025-27209, CVE-2025-2721020.19.4, 22.17.1, 24.4.1
January 202620, 22, 24, 25CVE-2025-55130, CVE-2025-55131, CVE-2025-5946520.20.0, 22.22.0, 24.13.0, 25.3.0
March 202620, 22, 24, 25CVE-2026-21637, CVE-2026-2171020.20.2, 22.22.2, 24.14.1, 25.8.2
June 202622, 24, 26CVE-2026-48933, CVE-2026-4861822.23.0, 24.17.0, 26.3.1
July 202622, 24, 26CVE-2026-56846, CVE-2026-56848, CVE-2026-5804322.23.2, 24.18.1, 26.5.1

Node.js 18 drops out after January 2025 and Node.js 20 after March 2026. Each release also fixed Medium and Low issues not listed here; the announcements on nodejs.org have the full lists.

Notable Node.js CVEs by release line

CVSS is NVD's own score where NVD has analysed the record and the score filed by the CNA, HackerOne, where it has not. Many Node.js records sit in NVD's Deferred status, so the two sources are mixed.

CVEIssueCVSSFixed inEnd-of-life lines
CVE-2025-55130Permission model bypass with crafted relative symlinks gives file read and write outside the allowlist9.1 (NVD)20.20.0, 22.22.0, 24.13.0, 25.3.018 not patched
CVE-2026-58043Permission model path matching over-grants file system access across prefix boundaries8.4 (NVD)22.23.2, 24.18.1, 26.5.120 and 18 not patched
CVE-2025-23083Permission model: diagnostics_channel exposes internal worker constructors7.720.18.2, 22.13.1, 23.6.1Not listed for 18
CVE-2025-23166An error in a background cryptographic operation crashes the process7.520.19.2, 22.15.1, 23.11.1, 24.0.218 not patched
CVE-2025-27210Windows device names such as CON, PRN and AUX bypass path traversal protection (incomplete fix for CVE-2025-23084)7.520.19.4, 22.17.1, 24.4.118 not patched
CVE-2025-27209HashDoS reintroduced by the V8 string hashing change in Node.js 247.524.4.124 only
CVE-2025-59465A malformed HTTP/2 HEADERS frame crashes the process7.520.20.0, 22.22.0, 24.13.0, 25.3.018 not patched
CVE-2025-59466Stack overflow errors become uncatchable when async_hooks is enabled7.5 (NVD)20.20.0, 22.22.0, 24.13.0, 25.3.018 not patched
CVE-2025-55131Buffer.alloc and Uint8Array can return memory that is not zero-filled when a vm timeout interrupts allocation7.120.20.0, 22.22.0, 24.13.0, 25.3.018 not patched
CVE-2026-21637Exceptions in TLS PSK, ALPN and SNI callbacks crash the server or leak file descriptors7.5 (NVD)20.20.0, 22.22.0, 24.13.0, 25.3.0; completed in 20.20.2, 22.22.2, 24.14.1, 25.8.2NVD range starts at 4.0.0
CVE-2026-21710A header named __proto__ crashes servers that read req.headersDistinct7.520.20.2, 22.22.2, 24.14.1, 25.8.2NVD range covers every release to 20.20.1
CVE-2026-48933WebCrypto AES input that is a multiple of 2 GiB crashes the process7.522.23.0, 24.17.0, 26.3.120 and 18 not patched
CVE-2026-48618Unicode dot separators can bypass the TLS wildcard depth check, because the resolver and the verifier normalise hostnames differently6.5 (NVD)22.23.0, 24.17.0, 26.3.120 and 18 not patched
CVE-2026-56846Retained HTTP/2 header blocks evade maxSessionMemory, allowing remote memory exhaustion7.522.23.2, 24.18.120 and 18 not patched
CVE-2026-56848Re-entrant HTTP/2 send causes a heap use-after-free7.522.23.2, 24.18.1, 26.5.120 and 18 not patched

"Not patched" means the line was out of support when the fix shipped and the project did not assess it. Under the project's policy, treat it as affected.

Node.js 26

Node.js 26 was released in May 2026 and has had two security releases, in June and July 2026. It becomes LTS on 28 October 2026 and is supported until 30 April 2029. The latest release at the time of writing is 26.10.0. Node.js 27 is scheduled for April 2027, with end of life on 30 April 2030.

Node.js 24

Node.js 24 has been patched in every security release since May 2025 and is supported until 30 April 2028. It moves from Active LTS to Maintenance on 20 October 2026. One CVE affects 24 alone: CVE-2025-27209, a HashDoS that came back with the V8 version Node.js 24 shipped, fixed in 24.4.1.

Node.js 22

Node.js 22 has been in Maintenance LTS since October 2025 and reaches end of life on 30 April 2027, less than seven months away. It has been patched in every security release in the table above, and its current release is 22.23.3. It is the next line to drop out of security releases, so estates on 22 should plan the move to 24 or 26 now.

Node.js 20

Node.js 20 reached end of life on 30 April 2026. Its last release, 20.20.2 in March 2026, fixed CVE-2026-21637 and CVE-2026-21710. The June and July 2026 security releases then fixed five CVEs that Node.js rated High (CVE-2026-48933, CVE-2026-48618, CVE-2026-56846, CVE-2026-56848 and CVE-2026-58043) on 22, 24 and 26 only. The project did not assess 20 for any of them. See Node.js 20 end of life.

Node.js 18

Node.js 18 reached end of life on 30 April 2025. Its last security release was 18.20.6 in January 2025, and its final release was 18.20.8 in March 2025. Six security releases have shipped since without an 18.x build, and between them they fixed 13 CVEs that Node.js rated High. Some apply only to features or V8 versions in newer lines, such as the permission model CVEs and CVE-2025-27209, but HTTP/2, TLS and HTTP header crashes such as CVE-2025-59465 and CVE-2026-21710 sit in code that Node.js 18 also has. See Node.js 18 end of life.

Node.js 16 and older

Node.js 16 reached end of life on 11 September 2023, and its final release was 16.20.2 in August 2023. It has missed every security release since, including all of the ones above. See Node.js 16 end of life.

Node.js remote code execution CVEs

Code execution bugs are rare in Node.js core. Most core CVEs are denial of service, request smuggling, TLS verification mistakes or permission model bypasses. The ones closest to code execution are these:

  • CVE-2024-27980 (8.1). On Windows, child_process.spawn and spawnSync handled batch files in a way that let a malicious argument inject commands even with the shell option disabled. Fixed in April 2024 in 18.20.2, 20.12.2 and 21.7.3.
  • CVE-2024-36138 (8.1). A bypass of that fix using other batch file extensions, fixed in July 2024 in 18.20.4, 20.15.1 and 22.4.1. Node.js 16 has neither fix.
  • CVE-2026-56848 (7.5). A heap use-after-free in HTTP/2 handling, which is a memory safety bug in code that parses network input. Fixed in 22.23.2, 24.18.1 and 26.5.1, with no fix for 20 or 18.
  • CVE-2025-55130 (9.1) and CVE-2026-58043 (8.4). These matter if you rely on the --permission flag to contain untrusted code, because both let that code read or write files outside its allowlist.

Many code execution findings in Node.js applications come from npm dependencies rather than the runtime. Those are fixed by upgrading the dependency, and a runtime upgrade does not touch them.

What to do on each line

  • 26 and 24. Stay on the latest patch release. Security releases have come every few months, with no fixed calendar.
  • 22. Stay current, and schedule the move before 30 April 2027.
  • 20 and 18. Upgrade to 22 or later, or take patched builds from a supplier that backports fixes. Pinning to 20.20.2 or 18.20.8 leaves every CVE fixed since then open.

Where OSSeva fits

OSSeva backports Node.js security fixes, including V8 and libuv CVEs, to end-of-life lines from 14.x to 20.x, and ships them as signed builds through Docker images, apt, yum or plain binaries. They are available now on the Patch, Assure and Operate tiers. Assure adds transitive npm dependency scanning and a SOC 2 and PCI DSS attestation package, and Operate adds 24/7 runtime monitoring with named Node.js engineers. See Node.js support and the Node.js end of life tracker.

Tags

Node.jsCVENode.js 20Node.js 18End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.