Node.js 24.13.0 LTS (Krypton) is a security release addressing six CVEs. The fixes include adding a default TLSSocket error handler, disabling futimes when permission model is enabled, requiring full read/write permissions for symlink APIs, handling stack overflow exceptions in async_hooks, refactoring unsafe buffer creation to remove zero-fill toggle, and routing TLS callback exceptions through error handlers. The release also updates c-ares to v1.34.6 and undici to 7.18.2.
Sort: