Change8
Symbol23 releases

http2

Found in 4 packages: envoy, node-js, deno, axios

envoy(5 releases)

node-js(15 releases)

v24.18.1
Jul 29, 2026

This is a security release addressing multiple vulnerabilities across http2, permission, https, sqlite, dns, zlib, and http modules. It also includes dependency updates for llhttp and undici.

v26.5.1
Jul 29, 2026

This is a security release addressing multiple vulnerabilities across various modules including http2, permission, https, sqlite, dns, zlib, and http. It also includes dependency updates for llhttp and undici.

v22.23.2
Jul 29, 2026

This is a security release that addresses several vulnerabilities across http2, permission, https, dns, zlib, and http modules. It also includes dependency updates for llhttp and undici.

v26.3.1
Jun 18, 2026

This is a security release addressing multiple high and medium severity vulnerabilities across TLS, crypto, HTTP/2, DNS, and permission handling modules. Key fixes involve input validation and boundary checks to prevent potential exploits.

v24.17.0
Jun 18, 2026

This is a security release addressing multiple high and medium severity CVEs across TLS, crypto, HTTP/2, and DNS modules. It also includes dependency upgrades for nghttp2, llhttp, openssl, and undici.

v22.23.0Breaking
Jun 18, 2026

This is a security release addressing multiple high and medium severity CVEs across TLS, crypto, HTTP/2, and DNS modules. It also includes dependency updates and removes deprecated http2 priority signaling.

v24.15.0
Apr 16, 2026

This release introduces several new features across CLI, crypto, fs, and stream modules, stabilizes ESM require and module caching, and includes numerous performance improvements and bug fixes across core modules.

v25.7.0
Feb 24, 2026

This release introduces HTTP/1 fallback configuration for http2, supports ESM entry points in SEA, and marks the sqlite module as a release candidate. It also includes several documentation improvements and dependency updates.

v20.19.6
Nov 25, 2025

This release focuses on security updates including root certificate renewals and OpenSSL 3.0.17, alongside the deprecation of HTTP/2 priority signaling and various dependency bumps.

v22.21.1
Oct 28, 2025

This release focuses on performance optimizations for array inspection and HTTP/2, along with critical bug fixes for process execution environment variables and async context handling during unhandled rejections.

v24.3.0
Jun 24, 2025

This release introduces the fileURLToPathBuffer API, object property mocking in the test runner, and stabilizes type stripping by removing its experimental warning. It also includes significant dependency updates and reverts changes to test_runner promises.

v18.20.6
Jan 21, 2025

This security release addresses three medium-severity vulnerabilities (CVE-2025-23085, CVE-2025-23084, CVE-2025-22150) involving HTTP2 memory leaks, Windows path traversal, and undici fetch randomness.

v20.18.2Breaking
Jan 21, 2025

This security release addresses several vulnerabilities including a high-severity issue in the Permission Model, path traversal on Windows, and memory leaks in HTTP/2.

v22.13.1Breaking
Jan 21, 2025

This security release addresses critical vulnerabilities including a path traversal on Windows, an HTTP/2 memory leak, and unauthorized InternalWorker access when the permission model is active.

v23.6.1Breaking
Jan 21, 2025

Security release addressing multiple CVEs including path traversal on Windows, HTTP/2 memory leaks, and permission model bypasses.

deno(2 releases)

axios(1 releases)

Track Symbol Changes

Use the Change8 MCP server or GitHub Action to get notified when http2 changes.

Learn More