Skip to content

[js] Update Node.js 26.3.0 → 26.3.1#1562

Merged
mockdeep merged 1 commit into
mainfrom
depfu/engine/pnpm/nodejs-26.3.1
Jun 25, 2026
Merged

[js] Update Node.js 26.3.0 → 26.3.1#1562
mockdeep merged 1 commit into
mainfrom
depfu/engine/pnpm/nodejs-26.3.1

Conversation

@depfu

@depfu depfu Bot commented Jun 25, 2026

Copy link
Copy Markdown
Contributor

Here is everything you need to know about this upgrade. Please take a good look at what changed and the test results before merging this pull request.

What changed?

Release Notes

26.3.1

This is a security release.

Notable Changes

  • (CVE-2026-48618) tls: normalize hostname for server identity checks (Matteo Collina) – High
  • (CVE-2026-48933) crypto: guard WebCrypto cipher output length (Filip Skokan) – High
  • (CVE-2026-48615) lib,test: redact proxy credentials in tunnel errors (Matteo Collina) – Medium
  • (CVE-2026-48619) http2: cap originSet size to prevent unbounded memory growth (Matteo Collina) – Medium
  • (CVE-2026-48928) tls: fix case-sensitive SNI context matching (Matteo Collina) – Medium
  • (CVE-2026-48930) dns,net: reject hostnames with embedded NUL bytes (Matteo Collina) – Medium
  • (CVE-2026-48934) tls: bind reusable sessions to authenticated host (Matteo Collina) – Medium
  • (CVE-2026-48617) permission: handle process.chdir on writereport (RafaelGSS) – Low
  • (CVE-2026-48931) http: fix response queue poisoning in http.Agent (Matteo Collina) – Low
  • (CVE-2026-48935) permission: disable FileHandle utimes with permission model (RafaelGSS) – Low
  • (CVE-2026-48936) permission: guard pipe open and chmod with net scope (RafaelGSS) – Low

Commits


All Depfu comment commands
@​depfu refresh
Rebases against your default branch and redoes this update
@​depfu recreate
Recreates this PR, overwriting any edits that you've made to it
@​depfu merge
Merges this PR once your tests are passing and conflicts are resolved
@​depfu close
Closes this PR and deletes the branch
@​depfu reopen
Restores the branch and reopens this PR (if it's closed)
@​depfu pause
Pauses all engine updates and closes this PR

@depfu depfu Bot added the depfu label Jun 25, 2026
@depfu depfu Bot assigned mockdeep Jun 25, 2026
@depfu depfu Bot requested a review from mockdeep June 25, 2026 00:00
@mockdeep mockdeep force-pushed the depfu/engine/pnpm/nodejs-26.3.1 branch from 898502a to d804d9a Compare June 25, 2026 17:25
@mockdeep mockdeep merged commit dc72ced into main Jun 25, 2026
3 checks passed
@mockdeep mockdeep deleted the depfu/engine/pnpm/nodejs-26.3.1 branch June 25, 2026 17:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant