Node.js 1.x — End of Life

EOL Critical risk
1 release in this series8 CVEs

Node.js 1.x has reached end of life and no longer receives security fixes. The most recent release in this series is 1.8.4. 8 CVEs are tracked for this series, including 1 critical. The next major version is Node.js 2. See Node.js 2 →

Node.js 1.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
1Jan 20, 2015—Yes1.8.4EOL

CVEs affecting Node.js 1.x (8)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-21717MEDIUM5.90.26%—1A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash col…Mar 30, 2026
CVE-2026-21716LOW3.30.14%—1An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without th…Mar 30, 2026
CVE-2026-21715LOW3.30.15%—1A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read pe…Mar 30, 2026
CVE-2026-21714MEDIUM5.30.45%—1A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) t…Mar 30, 2026
CVE-2026-21713MEDIUM5.90.38%—1A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potent…Mar 30, 2026
CVE-2026-21711MEDIUM5.30.17%—1A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the req…Mar 30, 2026
CVE-2026-21710HIGH7.525.04%—1A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `_…Mar 30, 2026
CVE-2024-3566CRITICAL9.86.88%—1A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d…Apr 10, 2024

Node.js 1.x is EOL — migrate to Node.js 2.x

Node.js 2.x is the next major release. Plan your upgrade before Node.js 1.x stops receiving security patches.

See Node.js 2.x

Add a Node.js 1 EOL badge to your README

Show your users which Node.js version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Node.js 1 EOL status
[![Node.js 1 EOL status](https://eolcanary.com/badge/nodejs/1.svg)](https://eolcanary.com/explore/nodejs/1)

Frequently asked questions

Is Node.js 1 end of life?

Yes. All Node.js 1.x releases have reached end of life and no longer receive security patches. There are 8 known CVEs affecting Node.js 1.x, including 1 critical. Migrate to Node.js 2.x as soon as possible.

What CVEs affect Node.js 1?

There are 8 CVEs tracked for Node.js 1.x, including 1 critical severity issue. See the full list above with CVSS and EPSS scores.

What is the latest Node.js 1 version?

The latest Node.js 1.x patch release is 1.8.4, released on July 9, 2015. Always run the latest patch to benefit from all security fixes.

How to migrate from Node.js 1 to Node.js 2?

To migrate from Node.js 1 to Node.js 2: (1) review the official Node.js 2 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Node.js 1 in production?

No. Node.js 1 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA