Skip to content

Node v22.23.2 nsolid v6.3.4 release - #502

Merged
santigimeno merged 16 commits into
node-v22.x-nsolid-v6.xfrom
node-v22.23.2-nsolid-v6.3.4-release
Jul 31, 2026
Merged

Node v22.23.2 nsolid v6.3.4 release#502
santigimeno merged 16 commits into
node-v22.x-nsolid-v6.xfrom
node-v22.23.2-nsolid-v6.3.4-release

Conversation

@santigimeno

Copy link
Copy Markdown
Member

No description provided.

RafaelGSS and others added 15 commits June 23, 2026 13:36
Signed-off-by: Matteo Collina <hello@matteocollina.com>
PR-URL: nodejs/node#63752
Reviewed-By: Tim Perry <pimterry@gmail.com>
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Reviewed-By: Gürgün Dayıoğlu <hey@gurgun.day>
CVE-ID: CVE-2026-56846
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: nodejs-private/node-private#927
CVE-ID: CVE-2026-56847
Signed-off-by: Matteo Collina <hello@matteocollina.com>
PR-URL: nodejs-private/node-private#921
Refs: https://hackerone.com/reports/3833629
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
CVE-ID: CVE-2026-56848
PR-URL: nodejs-private/node-private#934
Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
CVE-ID: CVE-2026-58040
Refs: https://hackerone.com/reports/3795657
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
PR-URL: nodejs-private/node-private#929
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
CVE-ID: CVE-2026-58042
(cherry picked from commit 0d3139ce8c35ac866ee77e116833e4a2b1eeea11)

PR-URL: nodejs-private/node-private#932
CVE-ID: CVE-2026-58044
PR-URL: nodejs/node#64714
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
Reviewed-By: Aviv Keller <me@aviv.sh>
Reviewed-By: Ulises Gascón <ulisesgascongonzalez@gmail.com>
Reviewed-By: Trivikram Kamat <trivikr.dev@gmail.com>
Reviewed-By: Juan José Arboleda <soyjuanarbol@gmail.com>
Signed-off-by: Paolo Insogna <paolo@cowtech.it>
PR-URL: nodejs-private/node-private#935
Refs: nodejs-private/llhttp-private#244
Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
This is a security release.

Notable changes:

* (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High
* (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High
* (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High
* (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium
* (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium
* (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium
* (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium
* (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low
* (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low
* (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low
* deps: update llhttp to 9.4.3 (Paolo Insogna)
* deps: update undici to 6.28.0 (Node.js GitHub Bot)

PR-URL: nodejs-private/node-private#938
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
2026-07-29 Node.js v22.23.2 Jod (LTS) Release
Git-EVTag-v0-SHA512: dd499ebdf24c64c6c4b036a919b098a7782ce28540746ad1bda363e2cb26f9ca6d49db784a4e042bed3995e399a97ca4d450b1c024d68c52d635b2606fce4baa
@santigimeno
santigimeno requested a review from RafaelGSS July 29, 2026 14:26
@santigimeno santigimeno self-assigned this Jul 29, 2026
@coderabbitai

coderabbitai Bot commented Jul 29, 2026

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: cd6df575-7806-42c5-99c1-50586f7737ec

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Comment @coderabbitai help to get the list of available commands.

Signed-off-by: Santiago Gimeno <santiago.gimeno@gmail.com>
@santigimeno
santigimeno force-pushed the node-v22.23.2-nsolid-v6.3.4-release branch from acf4c2b to 5127021 Compare July 29, 2026 14:45
@santigimeno
santigimeno merged commit 5127021 into node-v22.x-nsolid-v6.x Jul 31, 2026
19 of 24 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

6 participants