Fixed security issues: ACL revocation bypass in queued transactions and added cluster bus authentication warnings with a protected‑mode option.
Node.js changelog digest
Sep 14 - Sep 20, 2026. Useful releases, risky migrations, and noisy updates from the Node.js channel.
No matching updates in this bucket.
Node.js updates in 2026-w38
Fixed ACL revocation bypass where queued commands could access revoked keys
Fixed ACL revocation bypass where queued transaction commands could access revoked keys
Fixed ACL revocation issue allowing queued commands to access revoked keys
Adds security hardening for the cluster bus: warns on unauthenticated bus ports and introduces a protected mode option to enforce TLS authentication.
Added a generic MAC API and OpenSSL provider discovery for ciphers and hashes, plus new experimental DTLS and Web Workers support.