Node.js 3.x — End of Life
EOL Critical riskNode.js 3.x has reached end of life and no longer receives security fixes. The most recent release in this series is 3.3.1. 8 CVEs are tracked for this series, including 1 critical. The next major version is Node.js 4. See Node.js 4 →
Node.js 3.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 3 | Aug 4, 2015 | — | Yes | 3.3.1 | EOL |
CVEs affecting Node.js 3.x (8)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-21717 | MEDIUM | 5.9 | 0.26% | — | 3 | A flaw in V8's string hashing mechanism causes integer-like strings to be hashed to their numeric value, making hash col… | Mar 30, 2026 |
| CVE-2026-21716 | LOW | 3.3 | 0.14% | — | 3 | An incomplete fix for CVE-2024-36137 leaves `FileHandle.chmod()` and `FileHandle.chown()` in the promises API without th… | Mar 30, 2026 |
| CVE-2026-21715 | LOW | 3.3 | 0.15% | — | 3 | A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read pe… | Mar 30, 2026 |
| CVE-2026-21714 | MEDIUM | 5.3 | 0.45% | — | 3 | A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) t… | Mar 30, 2026 |
| CVE-2026-21713 | MEDIUM | 5.9 | 0.38% | — | 3 | A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potent… | Mar 30, 2026 |
| CVE-2026-21711 | MEDIUM | 5.3 | 0.17% | — | 3 | A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the req… | Mar 30, 2026 |
| CVE-2026-21710 | HIGH | 7.5 | 25.04% | — | 3 | A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `_… | Mar 30, 2026 |
| CVE-2024-3566 | CRITICAL | 9.8 | 6.88% | — | 3 | A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly d… | Apr 10, 2024 |
Node.js 3.x is EOL — migrate to Node.js 4.x
Node.js 4.x is the next major release. Plan your upgrade before Node.js 3.x stops receiving security patches.
Add a Node.js 3 EOL badge to your README
Show your users which Node.js version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/nodejs/3)Frequently asked questions
Is Node.js 3 end of life?
Yes. All Node.js 3.x releases have reached end of life and no longer receive security patches. There are 8 known CVEs affecting Node.js 3.x, including 1 critical. Migrate to Node.js 4.x as soon as possible.
What CVEs affect Node.js 3?
There are 8 CVEs tracked for Node.js 3.x, including 1 critical severity issue. See the full list above with CVSS and EPSS scores.
What is the latest Node.js 3 version?
The latest Node.js 3.x patch release is 3.3.1, released on September 15, 2015. Always run the latest patch to benefit from all security fixes.
How to migrate from Node.js 3 to Node.js 4?
To migrate from Node.js 3 to Node.js 4: (1) review the official Node.js 4 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Node.js 3 in production?
No. Node.js 3 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
