Node.js v26.5.1 records 10 CVE-tagged security changes
Node.js records v26.5.1 as a security release with ten CVE-tagged changes: two High, five Medium and three Low by the project's own ratings. The note includes concise patch descriptions across HTTP/2, HTTPS, permissions, SQLite, DNS, zlib and HTTP, plus llhttp 9.4.3 and undici 8.9.0 updates. It does not specify affected versions, vulnerability impact, exploitability, mitigations or upgrade guidance. [1]
This edition passed Imananq's enhanced publication checks. Some material claims remain explicitly attributed to official or company sources because no independent source is currently bound to this edition. The engine continues checking approved sources and will add corroboration only through a new edition that passes the full gate.

The Node.js project records v26.5.1 as a security release containing ten CVE-tagged changes, including two entries it rates High. The note identifies concrete code-change areas, but it does not establish affected earlier versions, exploitability or deployment-specific consequences. [1]
01
02
CVE-tagged changes listed by the project
The Node.js release record lists ten CVE-tagged changes.Changes rated High in the release record
The High-rated entries concern HTTP/2 and the permission system.Changes rated Medium in the release record
The Medium-rated entries concern HTTPS, SQLite, DNS and zlib.Changes rated Low in the release record
The Low-rated entries concern permissions and HTTP.Dependency versions recorded
The release also lists updates for llhttp and undici.Counts, severity labels and change descriptions are first-party statements in the Node.js release record. [1]
03
Security changes recorded
The Node.js project describes v26.5.1 as a security release and lists ten CVE-tagged changes. Its release record assigns two High, five Medium and three Low ratings. [1]
These descriptions state the patches recorded for particular subsystems. They do not, on their own, explain the vulnerability impact, show whether a deployment is affected, or establish exploitability. [1]
- High: CVE-2026-56848 defers an HTTP/2 RST stream while in scope; CVE-2026-58043 changes the permission system to avoid granting radix split nodes.
- Medium: CVE-2026-56850 distinguishes PFX object-array agent keys in HTTPS; CVE-2026-58040 binds identity checks to session reuse in HTTPS; CVE-2026-58041 invalidates SQLite tag-store iterators on statement reset.
- Medium: CVE-2026-58042 handles large DNS resolveAny address replies; CVE-2026-58045 throws on out-of-bounds zlib write buffers.
- Low: CVE-2026-56847 enforces filesystem write permission for trace events; CVE-2026-58039 checks the final report output path; CVE-2026-58044 rejects HTTP requests exceeding the maximum header count.
04
05
What the release note leaves open
The record gives maintainers a component-level list of the changes included in v26.5.1, including the patch context for each CVE-tagged item. It is insufficient by itself to determine exposure or urgency for a specific deployment. [1]
The primary source is the Node.js v26.5.1 release record on GitHub. [1]
- Affected versions and release lines: not stated.
- Exploitability and deployment-specific impact: not stated.
- Workarounds and official upgrade instructions: not supplied.
06
What maintainers can do
Use the release record as a starting point for review, not as deployment guidance. It does not state which Node.js release lines are affected, provide an upgrade path or workaround, or describe exploit status. [1]
- 01
Review the official v26.5.1 release record and its listed changes against the Node.js features enabled in your environment. [1]
- 02
Before making an update decision, consult current official support or advisory material for version scope and applicable upgrade guidance, which are not provided in this release record. [1]
07
Limits of this edition
The supplied release record does not identify affected Node.js release lines or versions for the individual CVEs. [1]
It provides concise patch descriptions but no vulnerability-impact descriptions, exploit status, workarounds, advisory links or official upgrade guidance. [1]
Severity ratings are the Node.js project's own labels in its release record. No independent advisory material was supplied. [1]
The supplied release text does not contain a publication date. [1]
SRC
Source desk
Direct links to the material behind this selection. Seeing the source matters as much as reading the synthesis.

