Sitelet https://github.com/nodejs/node/compare/nodejs:b4acf0c...nodejs:2645dc7
Skip to content
Permalink

Comparing changes

Choose two branches to see what’s changed or to start a new pull request. If you need to, you can also or learn more about diff comparisons.

Open a pull request

Create a new pull request by comparing changes across two branches. If you need to, you can also . Learn more about diff comparisons here.
base repository: nodejs/node
Failed to load repositories. Confirm that selected base ref is valid, then try again.
Loading
base: b4acf0c
Choose a base ref
...
head repository: nodejs/node
Failed to load repositories. Confirm that selected head ref is valid, then try again.
Loading
compare: 2645dc7
Choose a head ref
  • 18 commits
  • 960 files changed
  • 12 contributors

Commits on Mar 5, 2026

  1. Working on v22.22.2

    PR-URL: #61947
    marco-ippolito committed Mar 5, 2026
    Configuration menu
    Copy the full SHA
    bb73c10 View commit details
    Browse the repository at this point in the history

Commits on Mar 16, 2026

  1. lib: backport _tls_common and _tls_wrap refactors

    This is the same as the original change, minus the `process.emitWarning`
    calls and unit tests that expect the deprecation warnings.
    
    Original commit message:
        lib: deprecate _tls_common and _tls_wrap
    
        runtime deprecate the _tls_common and _tls_wrap
        modules, users should use nust node:tls insteal
        and internally internal/tls/commond and
        internal/tls/wrap should be used instead
    
    PR-URL: #57643
    Backport-PR-URL: #62231
    Co-authored-by: Antoine du Hamel <duhamelantoine1995@gmail.com>
    Co-authored-by: =?UTF-8?q?Micha=C3=ABl=20Zasso?= <targos@protonmail.com>
    Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
    Reviewed-By: Juan JosΓ© Arboleda <soyjuanarbol@gmail.com>
    3 people committed Mar 16, 2026
    Configuration menu
    Copy the full SHA
    73deff7 View commit details
    Browse the repository at this point in the history
  2. deps: upgrade npm to 10.9.6

    PR-URL: #62215
    Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
    Reviewed-By: Jordan Harband <ljharb@gmail.com>
    npm-cli-bot authored and aduh95 committed Mar 16, 2026
    Configuration menu
    Copy the full SHA
    d5ed384 View commit details
    Browse the repository at this point in the history

Commits on Mar 18, 2026

  1. deps: update undici to v6.24.1

    Signed-off-by: Matteo Collina <hello@matteocollina.com>
    PR-URL: #62285
    Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
    Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
    mcollina authored and aduh95 committed Mar 18, 2026
    Configuration menu
    Copy the full SHA
    859c8c7 View commit details
    Browse the repository at this point in the history

Commits on Mar 20, 2026

  1. deps: upgrade npm to 10.9.7

    PR-URL: #62330
    Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
    Reviewed-By: Richard Lau <richard.lau@ibm.com>
    npm-cli-bot authored Mar 20, 2026
    Configuration menu
    Copy the full SHA
    a688117 View commit details
    Browse the repository at this point in the history

Commits on Mar 22, 2026

  1. deps: V8: override depot_tools version

    For compatibility with Python >= 3.12 we need a newer version of
    `depot_tools` than is used for the older versions of V8.
    
    PR-URL: #62344
    Refs: nodejs/build#4278
    Reviewed-By: MichaΓ«l Zasso <targos@protonmail.com>
    Reviewed-By: Luigi Pinca <luigipinca@gmail.com>
    Reviewed-By: Colin Ihrig <cjihrig@gmail.com>
    Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
    richardlau authored and aduh95 committed Mar 22, 2026
    Configuration menu
    Copy the full SHA
    963c60a View commit details
    Browse the repository at this point in the history
  2. http: use null prototype for headersDistinct/trailersDistinct

    Use { __proto__: null } instead of {} when initializing the
    headersDistinct and trailersDistinct destination objects.
    
    A plain {} inherits from Object.prototype, so when a __proto__
    header is received, dest["__proto__"] resolves to Object.prototype
    (truthy), causing _addHeaderLineDistinct to call .push() on it,
    which throws an uncaught TypeError and crashes the process.
    
    Ref: https://hackerone.com/reports/3560402
    PR-URL: nodejs-private/node-private#821
    Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
    Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
    CVE-ID: CVE-2026-21710
    mcollina authored and aduh95 committed Mar 22, 2026
    Configuration menu
    Copy the full SHA
    a2fe9fd View commit details
    Browse the repository at this point in the history
  3. tls: wrap SNICallback invocation in try/catch

    Wrap the owner._SNICallback() invocation in loadSNI() with try/catch
    to route exceptions through owner.destroy() instead of letting them
    become uncaught exceptions. This completes the fix from CVE-2026-21637
    which added try/catch protection to callALPNCallback,
    onPskServerCallback, and onPskClientCallback but missed loadSNI().
    
    Without this fix, a remote unauthenticated attacker can crash any
    Node.js TLS server whose SNICallback may throw on unexpected input
    by sending a single TLS ClientHello with a crafted server_name value.
    
    Fixes: https://hackerone.com/reports/3556769
    Refs: https://hackerone.com/reports/3473882
    CVE-ID: CVE-2026-21637
    
    PR-URL: nodejs-private/node-private#819
    Reviewed-By: Robert Nagy <ronagy@icloud.com>
    Reviewed-By: Rafael Gonzaga <rafael.nunu@hotmail.com>
    CVE-ID: CVE-2026-21637
    mcollina authored and aduh95 committed Mar 22, 2026
    Configuration menu
    Copy the full SHA
    91b9708 View commit details
    Browse the repository at this point in the history
  4. crypto: use timing-safe comparison in Web Cryptography HMAC

    Use `CRYPTO_memcmp` instead of `memcmp` in `HMAC`
    Web Cryptography algorithm implementations.
    
    Ref: https://hackerone.com/reports/3533945
    Backport-PR-URL: nodejs-private/node-private#830
    Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
    PR-URL: nodejs-private/node-private#822
    CVE-ID: CVE-2026-21713
    panva authored and aduh95 committed Mar 22, 2026
    Configuration menu
    Copy the full SHA
    52a52ef View commit details
    Browse the repository at this point in the history
  5. src: handle NGHTTP2_ERR_FLOW_CONTROL error code

    Refs: https://hackerone.com/reports/3531737
    Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
    PR-URL: nodejs-private/node-private#832
    CVE-ID: CVE-2026-21714
    RafaelGSS authored and aduh95 committed Mar 22, 2026
    Configuration menu
    Copy the full SHA
    2a6105a View commit details
    Browse the repository at this point in the history
  6. permission: add permission check to realpath.native

    Signed-off-by: RafaelGSS <rafael.nunu@hotmail.com>
    PR-URL: nodejs-private/node-private#794
    Reviewed-By: Anna Henningsen <anna@addaleax.net>
    Reviewed-By: Marco Ippolito <marcoippolito54@gmail.com>
    Reviewed-By: Juan JosΓ© Arboleda <soyjuanarbol@gmail.com>
    Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
    CVE-ID: CVE-2026-21715
    RafaelGSS authored and aduh95 committed Mar 22, 2026
    Configuration menu
    Copy the full SHA
    db48d9c View commit details
    Browse the repository at this point in the history
  7. permission: include permission check on lib/fs/promises

    PR-URL: nodejs-private/node-private#795
    Reviewed-By: Anna Henningsen <anna@addaleax.net>
    Reviewed-By: Matteo Collina <matteo.collina@gmail.com>
    CVE-ID: CVE-2026-21716
    RafaelGSS authored and aduh95 committed Mar 22, 2026
    Configuration menu
    Copy the full SHA
    06fc343 View commit details
    Browse the repository at this point in the history
  8. deps: V8: backport 0a8b1cdcc8b2

    Original commit message:
    
        implement rapidhash secret generation
    
        Bug: 409717082
        Change-Id: I471f33d66de32002f744aeba534c1d34f71e27d2
        Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/6733490
        Reviewed-by: Leszek Swirski <leszeks@chromium.org>
        Commit-Queue: snek <snek@chromium.org>
        Cr-Commit-Position: refs/heads/main@{#101499}
    
    Refs: v8/v8@0a8b1cd
    Co-authored-by: Joyee Cheung <joyeec9h3@gmail.com>
    Backport-PR-URL: nodejs-private/node-private#833
    Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
    PR-URL: nodejs-private/node-private#809
    CVE-ID: CVE-2026-21717
    2 people authored and aduh95 committed Mar 22, 2026
    Configuration menu
    Copy the full SHA
    076acd0 View commit details
    Browse the repository at this point in the history
  9. deps: V8: backport 185f0fe09b72

    Original commit message:
    
        [numbers] Refactor HashSeed as a lightweight view over ByteArray
    
        Instead of copying the seed and secrets into a struct with value
        fields, HashSeed now stores a pointer pointing either into the
        read-only ByteArray, or the static default seed for off-heap
        HashSeed::Default() calls. The underlying storage is always
        8-byte aligned so we can cast it directly into a struct.
    
        Change-Id: I5896a7f2ae24296eb4c80b757a5d90ac70a34866
        Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/7609720
        Reviewed-by: Leszek Swirski <leszeks@chromium.org>
        Commit-Queue: Joyee Cheung <joyee@igalia.com>
        Cr-Commit-Position: refs/heads/main@{#105531}
    
    Refs: v8/v8@185f0fe
    Co-authored-by: Joyee Cheung <joyeec9h3@gmail.com>
    Backport-PR-URL: nodejs-private/node-private#833
    Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
    PR-URL: nodejs-private/node-private#809
    CVE-ID: CVE-2026-21717
    2 people authored and aduh95 committed Mar 22, 2026
    Configuration menu
    Copy the full SHA
    7dc00fa View commit details
    Browse the repository at this point in the history
  10. deps: V8: backport 1361b2a49d02

    Original commit message:
    
        [strings] improve array index hash distribution
    
        Previously, the hashes stored in a Name's raw_hash_field for decimal
        numeric strings (potential array indices) consist of the literal
        integer value along with the length of the string. This means
        consecutive numeric strings can have consecutive hash values, which
        can lead to O(n^2) probing for insertion in the worst case when e.g.
        a non-numeric string happen to land in the these buckets.
    
        This patch adds a build-time flag v8_enable_seeded_array_index_hash that
        scrambles the 24-bit array-index value stored in a Name's raw_hash_field
        to improve the distribution.
    
        x ^= x >> kShift; x = (x * m1) & kMask;    // round 1
        x ^= x >> kShift; x = (x * m2) & kMask;    // round 2
        x ^= x >> kShift;                          // finalize
    
        To decode, apply the same steps with the modular inverses of m1 and m2
        in reverse order.
    
        x ^= x >> kShift; x = (x * m2_inv) & kMask;    // round 1
        x ^= x >> kShift; x = (x * m1_inv) & kMask;    // round 2
        x ^= x >> kShift;                              // finalize
    
        where kShift = kArrayIndexValueBits / 2, kMask = kArrayIndexValueMask,
        m1, m2 (both odd) are the lower bits of the rapidhash secrets, m1_inv,
        m2_inv (modular inverses) are precomputed modular inverse of m1 and m2.
        The pre-computed values are appended to the hash_seed ByteArray in
        ReadOnlyRoots and accessed in generated code to reduce overhead.
        In call sites that don't already have access to the seeds, we read them
        from the current isolate group/isolate's read only roots.
    
        To consolidate the code that encode/decode these hashes, this patch
        adds MakeArrayIndexHash/DecodeArrayIndexFromHashField in C++ and CSA
        that perform seeding/unseeding if enabled, and updates places where
        encoding/decoding of array index is needed to use them.
    
        Bug: 477515021
        Change-Id: I350afe511951a54c4378396538152cc56565fd55
        Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/7564330
        Reviewed-by: Leszek Swirski <leszeks@chromium.org>
        Commit-Queue: Joyee Cheung <joyee@igalia.com>
        Cr-Commit-Position: refs/heads/main@{#105596}
    
    Refs: v8/v8@1361b2a
    Co-authored-by: Joyee Cheung <joyeec9h3@gmail.com>
    Backport-PR-URL: nodejs-private/node-private#833
    Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
    PR-URL: nodejs-private/node-private#809
    CVE-ID: CVE-2026-21717
    2 people authored and aduh95 committed Mar 22, 2026
    Configuration menu
    Copy the full SHA
    e3f4d6a View commit details
    Browse the repository at this point in the history

Commits on Mar 23, 2026

  1. build,test: test array index hash collision

    This enables v8_enable_seeded_array_index_hash and add a test for it.
    
    Fixes: https://hackerone.com/reports/3511792
    Backport-PR-URL: nodejs-private/node-private#833
    Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
    PR-URL: nodejs-private/node-private#809
    CVE-ID: CVE-2026-21717
    joyeecheung authored and aduh95 committed Mar 23, 2026
    Configuration menu
    Copy the full SHA
    6f14ee5 View commit details
    Browse the repository at this point in the history
  2. deps: V8: cherry-pick aac14dd95e5b

    Original commit message:
    
        [string] add 3rd round to seeded array index hash
    
        Since we already have 3 derived secrets, and arithmetics are
        relatively cheap, add a 3rd round to the xorshift-multiply
        seeding scheme. This brings the bias from ~3.4 to ~0.4.
    
        Bug: 477515021
        Change-Id: I1ef48954bcee8768d8c90db06ac8adb02f06cebf
        Reviewed-on: https://chromium-review.googlesource.com/c/v8/v8/+/7655117
        Reviewed-by: Chengzhong Wu <cwu631@bloomberg.net>
        Commit-Queue: Joyee Cheung <joyee@igalia.com>
        Reviewed-by: Leszek Swirski <leszeks@chromium.org>
        Cr-Commit-Position: refs/heads/main@{#105824}
    
    Refs: v8/v8@aac14dd
    Backport-PR-URL: nodejs-private/node-private#833
    Reviewed-By: Antoine du Hamel <duhamelantoine1995@gmail.com>
    PR-URL: nodejs-private/node-private#809
    CVE-ID: CVE-2026-21717
    joyeecheung authored and aduh95 committed Mar 23, 2026
    Configuration menu
    Copy the full SHA
    30a3ab1 View commit details
    Browse the repository at this point in the history
  3. 2026-03-24, Version 22.22.2 'Jod' (LTS)

    This is a security release.
    
    Notable changes:
    
    build,test,deps:
      * (CVE-2026-21717) test array index hash collision
    crypto:
      * (CVE-2026-21713) use timing-safe comparison in Web Cryptography HMAC
    http:
      * (CVE-2026-21710) use null prototype for headersDistinct/trailersDistinct
    permission:
      * (CVE-2026-21716) include permission check on lib/fs/promises
      * (CVE-2026-21715) add permission check to realpath.native
    src:
      * (CVE-2026-21714) handle NGHTTP2_ERR_FLOW_CONTROL error code
    tls:
      * (CVE-2026-21637) wrap SNICallback invocation in try/catch
    
    PR-URL: nodejs-private/node-private#844
    aduh95 committed Mar 23, 2026
    Configuration menu
    Copy the full SHA
    2645dc7 View commit details
    Browse the repository at this point in the history
Loading