Node.js 22.x — End of Life
Active Critical riskNode.js 22.x is still supported until Apr 30, 2027, in 205 days. The most recent release in this series is 22.23.3. 16 CVEs are tracked for this series, including 1 critical. The next major version is Node.js 23. See Node.js 23 →
Node.js 22.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 22LTS | Apr 24, 2024 | Oct 21, 2025 | Apr 30, 2027 | 22.23.3 | Active |
CVEs affecting Node.js 22.x (16)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-58043 | HIGH | 8.4 | 0.15% | — | 22 | A flaw in Node.js Permission Model enforcement can over-grant filesystem access across radix-tree prefix boundaries. … | Jul 30, 2026 |
| CVE-2026-56850 | MEDIUM | 4.4 | 0.08% | — | 22 | A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) cli… | Jul 30, 2026 |
| CVE-2026-56847 | MEDIUM | 6.1 | 0.15% | — | 22 | A flaw in Node.js Permission Model enforcement allows `trace_events.createTracing().enable()` Writes Trace Logs Outside … | Jul 30, 2026 |
| CVE-2026-48937 | HIGH | 7.5 | 0.57% | — | 22 | A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This v… | Jun 18, 2026 |
| CVE-2026-48617 | HIGH | 8.2 | 0.31% | — | 22 | A flaw in Node.js Permission Model enforcement allows Bypass via `process.report.writeReport()` Path Misvalidation. This… | Jun 18, 2026 |
| CVE-2026-21717 | MEDIUM | 5.9 | 0.26% | — | 22 | A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash col… | Mar 30, 2026 |
| CVE-2026-21716 | LOW | 3.3 | 0.14% | — | 22 | An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without th… | Mar 30, 2026 |
| CVE-2026-21715 | LOW | 3.3 | 0.15% | — | 22 | A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read pe… | Mar 30, 2026 |
| CVE-2026-21714 | MEDIUM | 5.3 | 0.45% | — | 22 | A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) t… | Mar 30, 2026 |
| CVE-2026-21713 | MEDIUM | 5.9 | 0.38% | — | 22 | A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potent… | Mar 30, 2026 |
| CVE-2026-21710 | HIGH | 7.5 | 25.04% | — | 22 | A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `_… | Mar 30, 2026 |
| CVE-2026-21637 | HIGH | 7.5 | 1.13% | — | 22 | A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCall… | Jan 20, 2026 |
| CVE-2025-59466 | HIGH | 7.5 | 0.69% | — | 22 | We have identified a bug in Node.js error handling where "Maximum call stack size exceeded" errors become uncatchable wh… | Jan 20, 2026 |
| CVE-2025-59465 | HIGH | 7.5 | 4.02% | — | 22 | A malformed `HTTP/2 HEADERS` frame with oversized, invalid `HPACK` data can cause Node.js to crash by triggering an unha… | Jan 20, 2026 |
| CVE-2025-55132 | MEDIUM | 5.3 | 0.26% | — | 22 | A flaw in Node.js's permission model allows a file's access and modification timestamps to be changed via `futimes()` ev… | Jan 20, 2026 |
| CVE-2025-55130 | CRITICAL | 9.1 | 1.72% | — | 22 | A flaw in Node.js’s Permissions model allows attackers to bypass `--allow-fs-read` and `--allow-fs-write` restrictions u… | Jan 20, 2026 |
Node.js 22.x will reach end of life — migrate to Node.js 23.x
Node.js 23.x is the next major release. Plan your upgrade before Node.js 22.x stops receiving security patches.
Add a Node.js 22 EOL badge to your README
Show your users which Node.js version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/nodejs/22)Frequently asked questions
Is Node.js 22 end of life?
No. Node.js 22.x is still supported until April 30, 2027. It continues to receive security patches and bug fixes.
What CVEs affect Node.js 22?
There are 16 CVEs tracked for Node.js 22.x, including 1 critical severity issue. See the full list above with CVSS and EPSS scores.
What is the latest Node.js 22 version?
The latest Node.js 22.x patch release is 22.23.3, released on September 23, 2026. Always run the latest patch to benefit from all security fixes.
How to migrate from Node.js 22 to Node.js 23?
To migrate from Node.js 22 to Node.js 23: (1) review the official Node.js 23 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Node.js 22 in production?
Yes, Node.js 22 is still supported. Support ends on April 30, 2027. Make sure you run the latest patch (22.23.3) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
