Two high-severity CVEs in HTTP/2 stream handling and permission radix trees require immediate upgrade; medium-severity fixes span DNS, HTTPS, SQLite, and zlib.
Summary
Production Node deployments using HTTP/2, permission model, or DNS resolution face exploitable gaps in this release. Upgrade path is direct—no breaking changes in patch version.
Why it matters
Production Node deployments using HTTP/2, permission model, or DNS resolution face exploitable gaps in this release. Upgrade path is direct—no breaking changes in patch version.
Implementation verdict
Straight replacement for 26.5.0 and earlier in Current track. No configuration changes needed. Install now if running any 26.x version; critical for HTTP/2 or permission-sandboxed workloads.
Sources
Dev Signal
Get briefs like this in your inbox — free, every weekday.
100+ sources compressed into one 4-minute read. Ranked, cited, implementation-ready.