Node v22.23.2 nsolid v6.3.4 release - #502
Merged
santigimeno merged 16 commits intoJul 31, 2026
Merged
Conversation
Signed-off-by: Matteo Collina <hello@matteocollina.com> PR-URL: nodejs/node#63752 Reviewed-By: Tim Perry <pimterry@gmail.com> Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com> Reviewed-By: Gürgün Dayıoğlu <hey@gurgun.day> CVE-ID: CVE-2026-56846
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com> PR-URL: nodejs-private/node-private#927 CVE-ID: CVE-2026-56847
Signed-off-by: Matteo Collina <hello@matteocollina.com> PR-URL: nodejs-private/node-private#921 Refs: https://hackerone.com/reports/3833629 Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com> CVE-ID: CVE-2026-56848
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com> PR-URL: nodejs-private/node-private#930 Refs: https://hackerone.com/reports/3816840 CVE-ID: CVE-2026-56850
Refs: https://hackerone.com/reports/3815767 Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com> PR-URL: nodejs-private/node-private#926 CVE-ID: CVE-2026-58039
PR-URL: nodejs-private/node-private#934 Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com> CVE-ID: CVE-2026-58040
Refs: https://hackerone.com/reports/3795657 Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com> PR-URL: nodejs-private/node-private#929 Reviewed-By: Matteo Collina <matteo.collina@gmail.com> CVE-ID: CVE-2026-58042
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com> PR-URL: nodejs-private/node-private#911 Refs: https://hackerone.com/reports/3761342 CVE-ID: CVE-2026-58043
(cherry picked from commit 0d3139ce8c35ac866ee77e116833e4a2b1eeea11) PR-URL: nodejs-private/node-private#932 CVE-ID: CVE-2026-58044
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com> PR-URL: nodejs-private/node-private#931 Refs: https://hackerone.com/reports/3857258 CVE-ID: CVE-2026-58045
PR-URL: nodejs/node#64714 Reviewed-By: Matteo Collina <matteo.collina@gmail.com> Reviewed-By: Aviv Keller <me@aviv.sh> Reviewed-By: Ulises Gascón <ulisesgascongonzalez@gmail.com> Reviewed-By: Trivikram Kamat <trivikr.dev@gmail.com> Reviewed-By: Juan José Arboleda <soyjuanarbol@gmail.com>
Signed-off-by: Paolo Insogna <paolo@cowtech.it> PR-URL: nodejs-private/node-private#935 Refs: nodejs-private/llhttp-private#244 Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
This is a security release. Notable changes: * (CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High * (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High * (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High * (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium * (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium * (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) – Medium * (CVE-2026-58045) zlib: throw on out-of-bounds write buffers (RafaelGSS) – Medium * (CVE-2026-56847) permission: enforce fs write permission for trace events (RafaelGSS) – Low * (CVE-2026-58039) permission: check final report output path (RafaelGSS) – Low * (CVE-2026-58044) http: reject requests exceeding max header count (Matteo Collina) – Low * deps: update llhttp to 9.4.3 (Paolo Insogna) * deps: update undici to 6.28.0 (Node.js GitHub Bot) PR-URL: nodejs-private/node-private#938 Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
2026-07-29 Node.js v22.23.2 Jod (LTS) Release Git-EVTag-v0-SHA512: dd499ebdf24c64c6c4b036a919b098a7782ce28540746ad1bda363e2cb26f9ca6d49db784a4e042bed3995e399a97ca4d450b1c024d68c52d635b2606fce4baa
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
Signed-off-by: Santiago Gimeno <santiago.gimeno@gmail.com>
santigimeno
force-pushed
the
node-v22.23.2-nsolid-v6.3.4-release
branch
from
July 29, 2026 14:45
acf4c2b to
5127021
Compare
RafaelGSS
approved these changes
Jul 29, 2026
EHortua
approved these changes
Jul 30, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.