Node.js 2.x — End of Life

EOL Critical risk
1 release in this series8 CVEs

Node.js 2.x has reached end of life and no longer receives security fixes. The most recent release in this series is 2.5.0. 8 CVEs are tracked for this series, including 1 critical. The next major version is Node.js 3. See Node.js 3 →

Node.js 2.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
2May 4, 2015—Yes2.5.0EOL

CVEs affecting Node.js 2.x (8)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-21717MEDIUM5.90.26%—2A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash col…Mar 30, 2026
CVE-2026-21716LOW3.30.14%—2An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without th…Mar 30, 2026
CVE-2026-21715LOW3.30.15%—2A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read pe…Mar 30, 2026
CVE-2026-21714MEDIUM5.30.45%—2A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) t…Mar 30, 2026
CVE-2026-21713MEDIUM5.90.38%—2A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potent…Mar 30, 2026
CVE-2026-21711MEDIUM5.30.17%—2A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the req…Mar 30, 2026
CVE-2026-21710HIGH7.525.04%—2A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `_…Mar 30, 2026
CVE-2024-3566CRITICAL9.86.88%—2A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d…Apr 10, 2024

Node.js 2.x is EOL — migrate to Node.js 3.x

Node.js 3.x is the next major release. Plan your upgrade before Node.js 2.x stops receiving security patches.

See Node.js 3.x

Add a Node.js 2 EOL badge to your README

Show your users which Node.js version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Node.js 2 EOL status
[![Node.js 2 EOL status](https://eolcanary.com/badge/nodejs/2.svg)](https://eolcanary.com/explore/nodejs/2)

Frequently asked questions

Is Node.js 2 end of life?

Yes. All Node.js 2.x releases have reached end of life and no longer receive security patches. There are 8 known CVEs affecting Node.js 2.x, including 1 critical. Migrate to Node.js 3.x as soon as possible.

What CVEs affect Node.js 2?

There are 8 CVEs tracked for Node.js 2.x, including 1 critical severity issue. See the full list above with CVSS and EPSS scores.

What is the latest Node.js 2 version?

The latest Node.js 2.x patch release is 2.5.0, released on July 28, 2015. Always run the latest patch to benefit from all security fixes.

How to migrate from Node.js 2 to Node.js 3?

To migrate from Node.js 2 to Node.js 3: (1) review the official Node.js 3 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Node.js 2 in production?

No. Node.js 2 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA