P.01Node.js June 2026 Security Release: 12 CVEs Patched, Including Two Auth Bypasses
Node.js pushed security updates on June 18, 2026 across v22, v24, and v26, patching 12 CVEs. Two are high-severity auth bypasses. The most interesting is undici's HTTP response queue poisoning, which can send the wrong response to the wrong request on keep-alive connections.






