Node.js 18.x — End of Life

EOL Actively exploited
EOL: Apr 30, 20251 release in this series10 CVEs

Node.js 18.x reached end of life on Apr 30, 2025, 525 days ago, and no longer receives security fixes. The most recent release in this series is 18.20.8. 10 CVEs are tracked for this series, including 1 critical and 1 actively exploited according to CISA KEV. 8 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Node.js 19. See Node.js 19 →

Node.js 18.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
18LTSApr 19, 2022Oct 18, 2023Apr 30, 202518.20.8EOL

CVEs affecting Node.js 18.x (10)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-21717MEDIUM5.90.26%—18A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash col…Mar 30, 2026
CVE-2026-21716LOW3.30.14%—18An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without th…Mar 30, 2026
CVE-2026-21715LOW3.30.15%—18A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read pe…Mar 30, 2026
CVE-2026-21714MEDIUM5.30.45%—18A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) t…Mar 30, 2026
CVE-2026-21713MEDIUM5.90.38%—18A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potent…Mar 30, 2026
CVE-2026-21711MEDIUM5.30.17%—18A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the req…Mar 30, 2026
CVE-2026-21710HIGH7.525.04%—18A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `_…Mar 30, 2026
CVE-2026-21637HIGH7.51.13%—18A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCall…Jan 20, 2026
CVE-2024-3566CRITICAL9.86.88%—18A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d…Apr 10, 2024
CVE-2023-44487HIGH7.599.99% KEV 18The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many…Oct 10, 2023

Node.js 18.x is EOL — migrate to Node.js 19.x

Node.js 19.x is the next major release. Plan your upgrade before Node.js 18.x stops receiving security patches.

See Node.js 19.x

Add a Node.js 18 EOL badge to your README

Show your users which Node.js version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Node.js 18 EOL status
[![Node.js 18 EOL status](https://eolcanary.com/badge/nodejs/18.svg)](https://eolcanary.com/explore/nodejs/18)

Frequently asked questions

Is Node.js 18 end of life?

Yes. All Node.js 18.x releases have reached end of life and no longer receive security patches. There are 10 known CVEs affecting Node.js 18.x, including 1 critical. Migrate to Node.js 19.x as soon as possible.

What CVEs affect Node.js 18?

There are 10 CVEs tracked for Node.js 18.x, including 1 critical severity issue and 1 listed in the CISA Known Exploited Vulnerabilities catalog. See the full list above with CVSS and EPSS scores.

What is the latest Node.js 18 version?

The latest Node.js 18.x patch release is 18.20.8, released on March 27, 2025. Always run the latest patch to benefit from all security fixes.

How to migrate from Node.js 18 to Node.js 19?

To migrate from Node.js 18 to Node.js 19: (1) review the official Node.js 19 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Node.js 18 in production?

No. Node.js 18 has reached end of life and security vulnerabilities are no longer patched. Critically, 1 CVE affecting Node.js 18.x is in the CISA KEV catalog — meaning it is actively exploited in the wild. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA