TypeScript 7.0.2 released as a patch update.
Node.js changelog updates
Node runtime, TypeScript, databases, containers, and backend observability. Follow release notes, breaking changes, security patches, pricing updates, and community reactions from this channel.
Use this Node.js changelog channel to compare product release notes, discover risky migrations, and build a weekly digest for the tools in this stack.
Products in this channel
Latest Node.js changelog updates
Fixed multiple critical security vulnerabilities including CVE‑2026‑62356, heap out‑of‑bounds write, use‑after‑free, and TLS client certificate authentication bypass.
Fixed several critical CVE‑2026‑62356 vulnerabilities: buffer overflow, out‑of‑bounds access, use‑after‑free, and ACL bypass in commands like SORT, GEORADIUS, and XREADGROUP.
Fixed multiple heap OOB write and use‑after‑free vulnerabilities in CMSketch loading, TopK cleanup, and TLS pending data handling.
Fixed multiple heap and out‑of‑bounds write vulnerabilities (CVE‑2026‑62356) including CMSketch RDB loading and TopK cleanup
Fixed multiple memory corruption vulnerabilities including OOB writes, use‑after‑free, and out‑of‑bounds reads in RDB loading, CMSketch, TopK cleanup, TLS pending data, ACL checks, and vector set handling.
Fixed multiple use‑after‑free vulnerabilities affecting TLS pending data handling and the blocked client list.
Fixed multiple use‑after‑free vulnerabilities in TLS pending data handling and blocked‑client list processing.