-
-
Notifications
You must be signed in to change notification settings - Fork 38.9k
Comparing changes
Open a pull request
base repository: nodejs/node
base: b4acf0c
head repository: nodejs/node
compare: 2645dc7
- 18 commits
- 960 files changed
- 12 contributors
Commits on Mar 5, 2026
-
Configuration menu - View commit details
-
Copy full SHA for bb73c10 - Browse repository at this point
Copy the full SHA bb73c10View commit details
Commits on Mar 16, 2026
-
lib: backport
_tls_commonand_tls_wraprefactorsThis is the same as the original change, minus the `process.emitWarning` calls and unit tests that expect the deprecation warnings. Original commit message: lib: deprecate _tls_common and _tls_wrap runtime deprecate the _tls_common and _tls_wrap modules, users should use nust node:tls insteal and internally internal/tls/commond and internal/tls/wrap should be used instead PR-URL: #57643 Backport-PR-URL: #62231 Co-authored-by: Antoine du Hamel <duhamelantoine1995@gmail.com> Co-authored-by: =?UTF-8?q?Micha=C3=ABl=20Zasso?= <targos@protonmail.com> Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com> Reviewed-By: Juan JosΓ© Arboleda <soyjuanarbol@gmail.com>Configuration menu - View commit details
-
Copy full SHA for 73deff7 - Browse repository at this point
Copy the full SHA 73deff7View commit details -
PR-URL: #62215 Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Jordan Harband <ljharb@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for d5ed384 - Browse repository at this point
Copy the full SHA d5ed384View commit details
Commits on Mar 18, 2026
-
deps: update undici to v6.24.1
Signed-off-by: Matteo Collina <hello@matteocollina.com> PR-URL: #62285 Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com> Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
Configuration menu - View commit details
-
Copy full SHA for 859c8c7 - Browse repository at this point
Copy the full SHA 859c8c7View commit details
Commits on Mar 20, 2026
-
PR-URL: #62330 Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com> Reviewed-By: Richard Lau <richard.lau@ibm.com>
Configuration menu - View commit details
-
Copy full SHA for a688117 - Browse repository at this point
Copy the full SHA a688117View commit details
Commits on Mar 22, 2026
-
deps: V8: override
depot_toolsversionFor compatibility with Python >= 3.12 we need a newer version of `depot_tools` than is used for the older versions of V8. PR-URL: #62344 Refs: nodejs/build#4278 Reviewed-By: MichaΓ«l Zasso <targos@protonmail.com> Reviewed-By: Luigi Pinca <luigipinca@gmail.com> Reviewed-By: Colin Ihrig <cjihrig@gmail.com> Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
Configuration menu - View commit details
-
Copy full SHA for 963c60a - Browse repository at this point
Copy the full SHA 963c60aView commit details -
http: use null prototype for headersDistinct/trailersDistinct
Use { __proto__: null } instead of {} when initializing the headersDistinct and trailersDistinct destination objects. A plain {} inherits from Object.prototype, so when a __proto__ header is received, dest["__proto__"] resolves to Object.prototype (truthy), causing _addHeaderLineDistinct to call .push() on it, which throws an uncaught TypeError and crashes the process. Ref: https://hackerone.com/reports/3560402 PR-URL: nodejs-private/node-private#821 Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com> Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com> CVE-ID: CVE-2026-21710Configuration menu - View commit details
-
Copy full SHA for a2fe9fd - Browse repository at this point
Copy the full SHA a2fe9fdView commit details -
tls: wrap SNICallback invocation in try/catch
Wrap the owner._SNICallback() invocation in loadSNI() with try/catch to route exceptions through owner.destroy() instead of letting them become uncaught exceptions. This completes the fix from CVE-2026-21637 which added try/catch protection to callALPNCallback, onPskServerCallback, and onPskClientCallback but missed loadSNI(). Without this fix, a remote unauthenticated attacker can crash any Node.js TLS server whose SNICallback may throw on unexpected input by sending a single TLS ClientHello with a crafted server_name value. Fixes: https://hackerone.com/reports/3556769 Refs: https://hackerone.com/reports/3473882 CVE-ID: CVE-2026-21637 PR-URL: nodejs-private/node-private#819 Reviewed-By: Robert Nagy <ronagy@icloud.com> Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com> CVE-ID: CVE-2026-21637
Configuration menu - View commit details
-
Copy full SHA for 91b9708 - Browse repository at this point
Copy the full SHA 91b9708View commit details -
crypto: use timing-safe comparison in Web Cryptography HMAC
Use `CRYPTO_memcmp` instead of `memcmp` in `HMAC` Web Cryptography algorithm implementations. Ref: https://hackerone.com/reports/3533945 Backport-PR-URL: nodejs-private/node-private#830 Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com> PR-URL: nodejs-private/node-private#822 CVE-ID: CVE-2026-21713
Configuration menu - View commit details
-
Copy full SHA for 52a52ef - Browse repository at this point
Copy the full SHA 52a52efView commit details -
src: handle NGHTTP2_ERR_FLOW_CONTROL error code
Refs: https://hackerone.com/reports/3531737 Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com> PR-URL: nodejs-private/node-private#832 CVE-ID: CVE-2026-21714
Configuration menu - View commit details
-
Copy full SHA for 2a6105a - Browse repository at this point
Copy the full SHA 2a6105aView commit details -
permission: add permission check to realpath.native
Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com> PR-URL: nodejs-private/node-private#794 Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com> Reviewed-By: Juan JosΓ© Arboleda <soyjuanarbol@gmail.com> Reviewed-By: Matteo Collina <matteo.collina@gmail.com> CVE-ID: CVE-2026-21715
Configuration menu - View commit details
-
Copy full SHA for db48d9c - Browse repository at this point
Copy the full SHA db48d9cView commit details -
permission: include permission check on lib/fs/promises
PR-URL: nodejs-private/node-private#795 Reviewed-By: Anna Henningsen <anna@addaleax.net> Reviewed-By: Matteo Collina <matteo.collina@gmail.com> CVE-ID: CVE-2026-21716
Configuration menu - View commit details
-
Copy full SHA for 06fc343 - Browse repository at this point
Copy the full SHA 06fc343View commit details -
deps: V8: backport 0a8b1cdcc8b2
Original commit message: implement rapidhash secret generation Bug: 409717082 Change-Id: I471f33d66de32002f744aeba534c1d34f71e27d2 Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/6733490 Reviewed-by: Leszek Swirski <leszeks@chromium.org> Commit-Queue: snek <snek@chromium.org> Cr-Commit-Position: refs/heads/main@{#101499} Refs: v8/v8@0a8b1cd Co-authored-by: Joyee Cheung <joyeec9h3@gmail.com> Backport-PR-URL: nodejs-private/node-private#833 Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com> PR-URL: nodejs-private/node-private#809 CVE-ID: CVE-2026-21717Configuration menu - View commit details
-
Copy full SHA for 076acd0 - Browse repository at this point
Copy the full SHA 076acd0View commit details -
deps: V8: backport 185f0fe09b72
Original commit message: [numbers] Refactor HashSeed as a lightweight view over ByteArray Instead of copying the seed and secrets into a struct with value fields, HashSeed now stores a pointer pointing either into the read-only ByteArray, or the static default seed for off-heap HashSeed::Default() calls. The underlying storage is always 8-byte aligned so we can cast it directly into a struct. Change-Id: I5896a7f2ae24296eb4c80b757a5d90ac70a34866 Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/7609720 Reviewed-by: Leszek Swirski <leszeks@chromium.org> Commit-Queue: Joyee Cheung <joyee@igalia.com> Cr-Commit-Position: refs/heads/main@{#105531} Refs: v8/v8@185f0fe Co-authored-by: Joyee Cheung <joyeec9h3@gmail.com> Backport-PR-URL: nodejs-private/node-private#833 Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com> PR-URL: nodejs-private/node-private#809 CVE-ID: CVE-2026-21717Configuration menu - View commit details
-
Copy full SHA for 7dc00fa - Browse repository at this point
Copy the full SHA 7dc00faView commit details -
deps: V8: backport 1361b2a49d02
Original commit message: [strings] improve array index hash distribution Previously, the hashes stored in a Name's raw_hash_field for decimal numeric strings (potential array indices) consist of the literal integer value along with the length of the string. This means consecutive numeric strings can have consecutive hash values, which can lead to O(n^2) probing for insertion in the worst case when e.g. a non-numeric string happen to land in the these buckets. This patch adds a build-time flag v8_enable_seeded_array_index_hash that scrambles the 24-bit array-index value stored in a Name's raw_hash_field to improve the distribution. x ^= x >> kShift; x = (x * m1) & kMask; // round 1 x ^= x >> kShift; x = (x * m2) & kMask; // round 2 x ^= x >> kShift; // finalize To decode, apply the same steps with the modular inverses of m1 and m2 in reverse order. x ^= x >> kShift; x = (x * m2_inv) & kMask; // round 1 x ^= x >> kShift; x = (x * m1_inv) & kMask; // round 2 x ^= x >> kShift; // finalize where kShift = kArrayIndexValueBits / 2, kMask = kArrayIndexValueMask, m1, m2 (both odd) are the lower bits of the rapidhash secrets, m1_inv, m2_inv (modular inverses) are precomputed modular inverse of m1 and m2. The pre-computed values are appended to the hash_seed ByteArray in ReadOnlyRoots and accessed in generated code to reduce overhead. In call sites that don't already have access to the seeds, we read them from the current isolate group/isolate's read only roots. To consolidate the code that encode/decode these hashes, this patch adds MakeArrayIndexHash/DecodeArrayIndexFromHashField in C++ and CSA that perform seeding/unseeding if enabled, and updates places where encoding/decoding of array index is needed to use them. Bug: 477515021 Change-Id: I350afe511951a54c4378396538152cc56565fd55 Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/7564330 Reviewed-by: Leszek Swirski <leszeks@chromium.org> Commit-Queue: Joyee Cheung <joyee@igalia.com> Cr-Commit-Position: refs/heads/main@{#105596} Refs: v8/v8@1361b2a Co-authored-by: Joyee Cheung <joyeec9h3@gmail.com> Backport-PR-URL: nodejs-private/node-private#833 Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com> PR-URL: nodejs-private/node-private#809 CVE-ID: CVE-2026-21717Configuration menu - View commit details
-
Copy full SHA for e3f4d6a - Browse repository at this point
Copy the full SHA e3f4d6aView commit details
Commits on Mar 23, 2026
-
build,test: test array index hash collision
This enables v8_enable_seeded_array_index_hash and add a test for it. Fixes: https://hackerone.com/reports/3511792 Backport-PR-URL: nodejs-private/node-private#833 Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com> PR-URL: nodejs-private/node-private#809 CVE-ID: CVE-2026-21717
Configuration menu - View commit details
-
Copy full SHA for 6f14ee5 - Browse repository at this point
Copy the full SHA 6f14ee5View commit details -
deps: V8: cherry-pick aac14dd95e5b
Original commit message: [string] add 3rd round to seeded array index hash Since we already have 3 derived secrets, and arithmetics are relatively cheap, add a 3rd round to the xorshift-multiply seeding scheme. This brings the bias from ~3.4 to ~0.4. Bug: 477515021 Change-Id: I1ef48954bcee8768d8c90db06ac8adb02f06cebf Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/7655117 Reviewed-by: Chengzhong Wu <cwu631@bloomberg.net> Commit-Queue: Joyee Cheung <joyee@igalia.com> Reviewed-by: Leszek Swirski <leszeks@chromium.org> Cr-Commit-Position: refs/heads/main@{#105824} Refs: v8/v8@aac14dd Backport-PR-URL: nodejs-private/node-private#833 Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com> PR-URL: nodejs-private/node-private#809 CVE-ID: CVE-2026-21717Configuration menu - View commit details
-
Copy full SHA for 30a3ab1 - Browse repository at this point
Copy the full SHA 30a3ab1View commit details -
2026-03-24, Version 22.22.2 'Jod' (LTS)
This is a security release. Notable changes: build,test,deps: * (CVE-2026-21717) test array index hash collision crypto: * (CVE-2026-21713) use timing-safe comparison in Web Cryptography HMAC http: * (CVE-2026-21710) use null prototype for headersDistinct/trailersDistinct permission: * (CVE-2026-21716) include permission check on lib/fs/promises * (CVE-2026-21715) add permission check to realpath.native src: * (CVE-2026-21714) handle NGHTTP2_ERR_FLOW_CONTROL error code tls: * (CVE-2026-21637) wrap SNICallback invocation in try/catch PR-URL: nodejs-private/node-private#844
Configuration menu - View commit details
-
Copy full SHA for 2645dc7 - Browse repository at this point
Copy the full SHA 2645dc7View commit details
This comparison is taking too long to generate.
Unfortunately it looks like we canβt render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff b4acf0c...2645dc7