← Back to events
ResolvedTechRelease24.18.1

2026-07-29, Version 24.18.1 'Krypton' (LTS), @juanarbol

Photo: Node.js Releases

What happened

This is a security release. Notable Changes ( CVE-2026-56846 ) http2: retain header memory in session accounting (Matteo Collina) – High ( CVE-2026-56848 ) http2: defer rst stream while in scope (Matteo Collina) – High ( CVE-2026-58043 ) permission: avoid granting radix split nodes (RafaelGSS) – High ( CVE-2026-56850 ) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium ( CVE-2026-58040 ) https: bind…

Summary assembled by rule from the sources below

Why it's spreading

Sources