Software Watch

Node.js (22) 22.23.2 重要

公開 · 検出 2026-09-19 セキュリティ 不具合修正

複数の脆弱性(CVE)が修正されました。HTTP/2、https、DNS、zlibなどのコンポーネントのセキュリティ問題に対応しており、早急な更新が推奨されます。

(CVE-2026-56846) http2: retain header memory in session accounting (Matteo Collina) – High (CVE-2026-56848) http2: defer rst stream while in scope (Matteo Collina) – High (CVE-2026-58043) permission: avoid granting radix split nodes (RafaelGSS) – High (CVE-2026-56850) https: distinguish PFX object-array agent keys (RafaelGSS) – Medium (CVE-2026-58040) https: bind identity checks to session reuse (Matteo Collina) – Medium (CVE-2026-58042) dns: handle large resolveAny address replies (RafaelGSS) –…

公式のリリース情報 → · Node.js (22) の履歴 · Node.js まとめ