Blog

Insights on software development, security, and technology from our team.

Showing posts taggednodejs

A polluted prototype can hijack your axios traffic. Upgrade to 1.18.0.

axios just disclosed CVE-2026-67320, a prototype pollution flaw in its Node.js HTTP adapter that can reroute your server's outbound requests through an attacker-controlled proxy and leak credentials over plaintext HTTP. It's a sharp reminder that a dependency you barely configure is still attack surface. Here's what to patch, and what to change beyond the patch.

Node.js is dropping odd-versus-even. Here's how to plan your upgrades now.

Node.js is retiring the odd-versus-even release model that backend teams have leaned on for a decade. Starting with version 27, there's one major a year, every release becomes LTS, and a new six-month Alpha channel opens this October. Here's what that changes if you run Node in production, and the one CI job to add now.