Node.js July 2026 Security Releases
By BIOS Founding Team

A coordinated security release across the 26.x, 24.x, and 22.x lines fixed 11 CVEs, including 3 HIGH-severity issues: an HTTP/2 flow-control bypass, an HTTP/2 re-entrant-send heap-use-after-free, and a Permission Model path-matching flaw that over-granted filesystem access.
It also patched several medium and low-severity issues in HTTPS Agent mTLS handling, node:sqlite, node:zlib, and DNS resolution, alongside undici and llhttp dependency bumps. If you run Node.js anywhere in production, releases like this are worth applying promptly.
Full details: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
More from the community

Stable and Longterm Kernel Updates: 7.2.4, 6.18.50, 6.12.109
Greg Kroah-Hartman pushed out new stable and longterm point releases across the 7.2, 6.18, and 6.12 lines, each bundling accumulated fixes across drivers, filesystems, and core subsystems.

Rust Debugging Survey 2026 Results
The Rust Project published results from its 2026 debugging survey, gathering community feedback on debugging tools and workflows to guide future tooling investment.

Docker Desktop 4.90.0
This release made 'Ask Gordon,' Docker's AI assistant, accessible as a persistent right-side drawer and added one-click AI diagnosis for containers, images, and volumes with detected issues.