- Fix multiple high‑severity CVEs across http2, https, permission, dns, sqlite, and zlib components
- Update dependencies: llhttp to 9.4.3 and undici to 7.29.0
- Improve HTTP handling: reject requests exceeding max header count and defer RST streams
Official Node.js changelog summary with source attribution, release tags, and community reactions.
Track this Node.js release note alongside related changelog updates, risky changes, and weekly digest signals from the developer community.
Every summary should remain traceable to the original changelog or release source.
Turn this Node.js release note into a weekly digest for the tools you actually use.
Create digestPatched numerous CVEs (high to low severity) across http2, permission, https, sqlite, dns, zlib, and http modules, enhancing security and stability.
Patched high‑severity CVEs across http2, http, https, dns, permission, and zlib modules, including header memory handling and identity checks.
Added new release key for signing future Node.js releases.