Node.js - v18.20.1

Security

This is a security release.

Notable Changes

  • CVE-2024-27983 - Assertion failed in node::http2::Http2Session::\~Http2Session() leads to HTTP/2 server crash- (High)
  • CVE-2024-27982 - HTTP Request Smuggling via Content Length Obfuscation - (Medium)
  • llhttp version 9.2.1
  • undici version 5.28.4

Commits


Details

date
April 3, 2024, 2:24 p.m.
name
2024-04-03, Version 18.20.1 'Hydrogen' (LTS), @RafaelGSS
type
Patch
👇
Register or login to:
  • 🔍View and search all Node.js releases.
  • 🛠️Create and share lists to track your tools.
  • 🚨Setup notifications for major, security, feature or patch updates.
  • 🚀Much more coming soon!
Continue with GitHub
Continue with Google
or