http2
Found in 4 packages: envoy, node-js, deno, axios
envoy(5 releases)
v1.36.10BreakingThis release addresses multiple security vulnerabilities across various components including URL normalization, HTTP/3, HTTP/2, admin, ext_authz, and QUIC. It also includes several bug fixes for filter management, ext_proc, and router functionalities.
v1.38.1BreakingThis release focuses heavily on security fixes, addressing vulnerabilities in HTTP/2 header limits, HMAC verification, and AES-CBC decryption. It also includes several bug fixes and minor behavior changes regarding upstream failure reasons and load balancer rebuild coalescing.
v1.37.3Release v1.37.3 includes several security fixes related to HTTP/2 header limits, HMAC verification, and AES-CBC decryption, alongside a fix for a load report shutdown race condition.
v1.36.7This release focuses on security fixes, addressing vulnerabilities in HTTP/2 header limits and OAuth2 HMAC verification, alongside a fix for a load report shutdown race condition.
v1.35.11This release focuses heavily on security fixes, addressing vulnerabilities in HTTP/2 header limits, HMAC verification, and AES-CBC decryption. It also introduces new features for periodic metric eviction and limiting stats scope size.
node-js(15 releases)
v24.18.1This is a security release addressing multiple vulnerabilities across http2, permission, https, sqlite, dns, zlib, and http modules. It also includes dependency updates for llhttp and undici.
v26.5.1This is a security release addressing multiple vulnerabilities across various modules including http2, permission, https, sqlite, dns, zlib, and http. It also includes dependency updates for llhttp and undici.
v22.23.2This is a security release that addresses several vulnerabilities across http2, permission, https, dns, zlib, and http modules. It also includes dependency updates for llhttp and undici.
v26.3.1This is a security release addressing multiple high and medium severity vulnerabilities across TLS, crypto, HTTP/2, DNS, and permission handling modules. Key fixes involve input validation and boundary checks to prevent potential exploits.
v24.17.0This is a security release addressing multiple high and medium severity CVEs across TLS, crypto, HTTP/2, and DNS modules. It also includes dependency upgrades for nghttp2, llhttp, openssl, and undici.
v22.23.0BreakingThis is a security release addressing multiple high and medium severity CVEs across TLS, crypto, HTTP/2, and DNS modules. It also includes dependency updates and removes deprecated http2 priority signaling.
v24.15.0This release introduces several new features across CLI, crypto, fs, and stream modules, stabilizes ESM require and module caching, and includes numerous performance improvements and bug fixes across core modules.
v25.7.0This release introduces HTTP/1 fallback configuration for http2, supports ESM entry points in SEA, and marks the sqlite module as a release candidate. It also includes several documentation improvements and dependency updates.
v20.19.6This release focuses on security updates including root certificate renewals and OpenSSL 3.0.17, alongside the deprecation of HTTP/2 priority signaling and various dependency bumps.
v22.21.1This release focuses on performance optimizations for array inspection and HTTP/2, along with critical bug fixes for process execution environment variables and async context handling during unhandled rejections.
v24.3.0This release introduces the fileURLToPathBuffer API, object property mocking in the test runner, and stabilizes type stripping by removing its experimental warning. It also includes significant dependency updates and reverts changes to test_runner promises.
v18.20.6This security release addresses three medium-severity vulnerabilities (CVE-2025-23085, CVE-2025-23084, CVE-2025-22150) involving HTTP2 memory leaks, Windows path traversal, and undici fetch randomness.
v20.18.2BreakingThis security release addresses several vulnerabilities including a high-severity issue in the Permission Model, path traversal on Windows, and memory leaks in HTTP/2.
v22.13.1BreakingThis security release addresses critical vulnerabilities including a path traversal on Windows, an HTTP/2 memory leak, and unauthorized InternalWorker access when the permission model is active.
v23.6.1BreakingSecurity release addressing multiple CVEs including path traversal on Windows, HTTP/2 memory leaks, and permission model bypasses.
deno(2 releases)
v2.9.4This release introduces new features like HMR for React Router and enhanced buffer manipulation in Node.js extensions, alongside numerous bug fixes across various modules including desktop, core, and npm operations.
v2.7.13This release introduces significant enhancements to Node.js compatibility, including rewriting node:http with llhttp and implementing the node:repl module. Numerous bug fixes address issues across HTTP/2, TLS, file system operations, and runtime stability.
axios(1 releases)
Track Symbol Changes
Use the Change8 MCP server or GitHub Action to get notified when http2 changes.
Learn More