// Node.js extended support

Node.js 18 extended support, and Node.js 20 after end of life.
The upgrade is usually the easy answer. When it is not, the runtime still needs fixes.

OSSeva provides Node.js extended support for 14, 16, 18 and 20, with patched runtimes that include V8 and libuv fixes after the Node.js project stops releasing them. Node.js 18 reached end of life on 30 April 2025 with 18.20.8, and Node.js 20 on 30 April 2026, with 20.20.2 as its last release. For most applications the better move is an upgrade to Node.js 24, or to 26 once it becomes LTS on 28 October 2026, and we will tell you so. Extended support is for runtimes held back by native modules, vendor certification or a release freeze. It is priced per application runtime.

Node.js 20Node.js 18Node.js 16Node.js 14Node.js 22

Trusted globally by enterprises

Henry ScheinEnbridgeGojekMicrosoft

Why Node.js 18 and 20 are still in production

Most Node.js upgrades are a test run and a rebuild. These are the reasons some services do not move.

End of life means known flaws stay open

The Node.js project states that an end-of-life line gets no new releases, even when a vulnerability fixed in a newer line also affects it. Node.js 20 has already missed two security releases, on 17 June and 28 July 2026, which shipped fixes for 22, 24 and 26 only.

Native modules decide the date

Native add-ons are compiled for one Node.js ABI: version 115 on Node.js 20, 127 on 22 and 137 on 24. Each one has to be rebuilt for the new line, and an add-on that no longer builds is what usually pins a service to 18 or 20.

Node.js 22 is a short stop

Node.js 22 reaches end of life on 30 April 2027. Node.js 24 is supported until 30 April 2028, and 26 until 30 April 2029 once it becomes LTS. A team that moves to 22 now faces the same exercise again within months.

The dates that matter

  1. 2025-03-27

    Node.js 18.20.8 released, the final 18.x release.

  2. 2025-04-30

    Node.js 18 reaches end of life.

  3. 2026-03-24

    Node.js 20.20.2 released, the final 20.x release.

  4. 2026-04-30

    Node.js 20 reaches end of life.

  5. 2026-06-17

    Security releases ship for Node.js 22, 24 and 26. None for 20.

  6. 2026-07-28

    A second round of security releases for 22, 24 and 26. None for 20.

  7. 2026-10-28

    Node.js 26 becomes an LTS line, supported until 30 April 2029.

  8. 2027-04-30

    Node.js 22 reaches end of life.

  9. 2028-04-30

    Node.js 24 reaches end of life.

What OSSeva delivers

1

Patched Node.js 14 to 20 runtimes

Security fixes backported to the Node.js line you run, with V8 and libuv CVEs included, delivered as signed Docker images in Alpine and Debian variants, apt and yum packages and binaries. You change the image tag and nothing else.

OSSeva PatchV8 and libuvSigned (GPG)
2

Dependency scanning and an upgrade plan

Transitive npm dependency scanning with a prioritised remediation report, an HTTP/2 and TLS configuration review, a container base image hardening review, a SOC 2 and PCI DSS attestation package and a plan for the move to a current LTS line.

OSSeva Assurenpm scanningUpgrade plan
3

Node.js operated

24/7 process and cluster health monitoring, event loop and memory leak alerting, PM2 and cluster mode support, a 15-minute P1 incident response SLA, a named senior Node.js engineer, and execution of the major version migration.

OSSeva Operate24/715-minute P1

Your options, compared

OptionWhat you getTrade-off
Upgrade to Node.js 24An LTS line the project supports until 30 April 2028Native add-ons are rebuilt and deprecated APIs cleared. For most applications this is the right answer.
Wait for Node.js 26 LTSThe longest runway, to 30 April 2029, from 28 October 2026The biggest jump from 18 or 20, and the project advises running only LTS lines in production, so not before that date.
Upgrade to Node.js 22The smallest step from 20End of life on 30 April 2027, so another upgrade follows soon.
Commercial support for end-of-life linesFixes for lines past Maintenance LTS, through the partners the Node.js project lists and other support companiesCheck what each one covers: the runtime only, or images, npm dependencies and operations too.
OSSeva extended supportPatched 14 to 20 runtimes, npm dependency scanning and help with the upgrade, on one contract with the rest of your stackA subscription priced per application runtime, for as long as you stay.
Stay unpatchedNothingNode.js services are usually internet-facing, and every new security release adds findings you cannot close.

Dates from the Node.js release schedule on GitHub and the nodejs.org release index, release policy and end-of-life pages, all checked on 9 October 2026. OSSeva coverage from the OSSeva Node.js technology page.

Frequently asked questions

When did Node.js 18 reach end of life?

On 30 April 2025. The final release was 18.20.8, published on 27 March 2025, and the Node.js project publishes no further 18.x releases.

When is Node.js 20 end of life?

Node.js 20 reached end of life on 30 April 2026. Its last release was 20.20.2 on 24 March 2026, and the security releases of June and July 2026 shipped no 20.x build.

Is there extended support for Node.js 18?

Yes, from commercial providers. The Node.js project points to its OpenJS Ecosystem Sustainability Program partners for lines past Maintenance LTS, and independent support companies such as OSSeva also patch them. OSSeva covers Node.js 14, 16, 18 and 20, including V8 and libuv fixes.

Which Node.js versions are supported now?

Node.js 22 until 30 April 2027 and Node.js 24 until 30 April 2028. Node.js 26 becomes LTS on 28 October 2026 and is supported until 30 April 2029.

Should we upgrade instead of buying extended support?

Usually, yes. For most applications moving to 24 means a test run and a rebuild of native add-ons. Extended support is for runtimes that cannot move yet because of a native dependency, a vendor certification or a release freeze.

Does OSSeva support current Node.js versions?

Yes. Node.js 22 is covered alongside the patched 14 to 20 lines, and OSSeva Assure plans the move to a current LTS line.

Do the patched images work with our Kubernetes manifests?

Yes. OSSeva publishes patched Node.js Docker images in Alpine and Debian variants. You update the image tag in your manifests and nothing else changes.

How is it priced?

Per application runtime. The tier you choose, Patch, Assure or Operate, sets how much of the work OSSeva takes on. Book a discovery call for a quote.

Upgrade what you can. Patch what you cannot.

Book a discovery call with your Node.js versions and native dependencies, and we will send a quote priced per application runtime.