The Node.js Security Bug Bounty Program has been temporarily paused due to a lack of funding. This decision may impact the process for reporting and addressing potential security vulnerabilities, and the Node.js project is actively seeking alternative solutions.
Node.js 25.9.0 has been released as a Current version, bringing the latest features and improvements. This release is primarily aimed at developers looking to test new functionalities and adopt them early. For stable production environments, using an LTS version is recommended.
A new integer hash function for the V8 engine has been developed, offering minimal HashDoS resistance while remaining quickly reversible. This is a significant improvement for Node.js applications, enhancing internal security and performance stability. Developers can expect a more robust runtime without direct API changes.
Node.js 25.8.2 (Current) has been released. This is a patch release primarily focused on bug fixes and stability improvements. Developers using the Current branch are encouraged to upgrade for the latest stability enhancements.
Node.js 24.14.1 (LTS) is the latest patch release for the Node.js 24 Long Term Support (LTS) line. This update primarily focuses on enhancing stability, addressing potential bugs, and strengthening security, contributing to the robustness of production environments. All developers are recommended to apply this update to maintain stable application operations.
Node.js 22.22.2, the latest patch release for the Node.js 22 LTS series, has been announced. This update focuses on improving stability and reliability through various bug fixes and internal dependency updates. All users on Node.js 22 LTS are encouraged to upgrade promptly to ensure a stable operating environment.
Node.js 20.20.2 LTS is a patch release focused on enhancing stability and reliability. This update includes important bug fixes and performance improvements, providing the latest stability for all developers using the Node.js 20 LTS branch. Updating is recommended to ensure smooth operation in production environments.
Critical security vulnerabilities addressed in Node.js versions across multiple release lines requiring immediate updates. These releases fix high-severity issues including potential remote code execution and denial of service vulnerabilities that could impact production applications.