Evidence-linked product lifecycle intelligenceSUPPORT · SECURITY · RETIREMENT
← Lifecycle catalogue
RELEASE NOTESOPENJS FOUNDATIONVERIFIED

PUBLISHER UPDATE · NODEJS-24.20.0

NODEJS-24.20.0 release notes and known issues

2026-08-26, Version 24.20.0 'Krypton' (LTS), @aduh95

Scope: Node.js. This update record adds version, fix and known-issue context. Its publication date is not a lifecycle boundary.

Summary

Notable Changes [ b12bcc9ae1 ] - (SEMVER-MINOR) async_hooks : add using scopes to AsyncLocalStorage (Stephen Belanger) #61674 [ e2eb88b36b ] - (SEMVER-MINOR) buffer : add end parameter (Robert Nagy) #62390 [ 1fefdda18e ] - crypto : update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746 [ 4a158cf1ab ] - doc : add MikeMcC399 as collaborator (Mike McCready) #64656 [ d4cafce076 ] - (SEMVER-MINOR) lib,permission : add permission.drop (Rafael Gonzaga) #62672 [ b3cfb55267 ] - (SEMVER-MINOR) loader : implement package maps (Maël Nison) #62239 [ cd1eb3e60b ] - (SEMVER-MINOR) src,permission : add --permission-audit (RafaelGSS) #61869 [ 28dc85d8d2 ] - (SEMVER-MINOR) stream : add node:stream/iter implementation (James M Snell) #62066 [ d31c168740 ] - (SEMVER-MINOR) test_runner : add context.log() and test:log event (Moshe Atlow) #64389 [ add1edbc42 ] - (SEMVER-MINOR) test_runner : report entryFile in TestStream events (Moshe Atlow) #64309 [ d937c8c6cd ] - (SEMVER-MINOR) wasm : enable JSPI (Guy Bedford) #59941 Commits [ 1822c0f335 ] - assert,util : fix TypeError on Maps with null keys (Paul Bouchon) #64441 [ b12bcc9ae1 ] - (SEMVER-MINOR) async_hooks : add using scopes to AsyncLocalStorage (Stephen Belanger) #61674 [ 984260bf44 ] - async_hooks : use validateBoolean for trackPromises (Soul Lee) #64731 [ ba2612cca2 ] - benchmark : fix calibrate-n option handling (Luan Muniz) #64146 [ 236dc4d2d7 ] - benchmark : add bytes variant to webstreams async-iterator (Matteo Collina) #64291 [ b022a1419c ] - benchmark : respect stream/iter broadcast backpressure (Trivikram Kamat) #63314 [ a290f51f15 ] - (SEMVER-MINOR) benchmark : add benchmarks for experimental stream/iter (James M Snell) #62066 [ 465f2bfb74 ] - buffer : use Clamp conversion in Blob slice (Donghoon Kang) #64739 [ 74a22cd0c5 ] - buffer : validate copyArrayBuffer offsets against buffer length (Ilia Alshanetsky) #63904 [ 21e24208dc ] - buffer : normalize lone "\r" in Blob native line endings (Daijiro Wachi) #64115 [ ddacb3ff10 ] - buffer : fix Blob.stream() leaking source buffer (semimikoh) #63577 [ 49198d2313 ] - buffer : fix end parameter bugs in indexOf/lastIndexOf (Robert Nagy) #62711 [ e2eb88b36b ] - (SEMVER-MINOR) buffer : add end parameter (Robert Nagy) #62390 [ e2e5c4fe88 ] - build : update binary-upload to use correct tarball name (Stewart X Addison) #65282 [ b78a212553 ] - build : pin envinfo versions in github actions (Joyee Cheung) #64117 [ 094fb840aa ] - build : add QUIC CI job for PRs matching QUIC related paths (Tim Perry) #63875 [ 91f5003cad ] - build : fix flags for ngtcp2 on IBM i (SRAVANI GUNDEPALLI) #60073 [ e83648effd ] - build,test : add tests for binary linked with shared libnode (Joyee Cheung) #61463 [ 4a425b41d9 ] - build,tools : fix shared library cross-compile (Kirill Saied) #63963 [ fe8fa45ff2 ] - cli : style node --help output with util.styleText (Adrián Estrada) #64484 [ 3cd1576cb2 ] - crypto : preserve OpenSSL errors from KDF failures (Filip Skokan) #64776 [ 74b3023565 ] - crypto : handle XOF output allocation failure (Filip Skokan) #64851 [ fea0666a1b ] - crypto : clarify missing cipher error (Filip Skokan) #64852 [ 33fec91b54 ] - crypto : reuse X509 issuer result (Filip Skokan) #64852 [ 44c1473348 ] - crypto : validate key generation options (Filip Skokan) #64852 [ c2c53a18e5 ] - crypto : fix Argon2 validation errors (Filip Skokan) #64852 [ edc1f2126d ] - crypto : initialize KeyObjectData mutex eagerly (Filip Skokan) #64851 [ be8237240c ] - crypto : handle DH operation failures (Filip Skokan) #64851 [ b65a8f3875 ] - crypto : preserve RSA-PSS legacy pubkey DER (Filip Skokan) #64547 [ 49f2ae204b ] - crypto : cleanse provider private key copies (Filip Skokan) #64547 [ a5d4ac8208 ] - crypto : handle incomplete RSA private keys (Filip Skokan) #64547 [ b72c0b9616 ] - crypto : retain legacy DH validation (Filip Skokan) #64547 [ 24a1be5886 ] - crypto : limit KangarooTwelveParams customization to 512 bytes (Filip Skokan) #64557 [ 0290e0a61e ] - crypto : sp

Improvements and security content

  • Notable Changes [ b12bcc9ae1 ] - (SEMVER-MINOR) async_hooks : add using scopes to AsyncLocalStorage (Stephen Belanger) #61674 [ e2eb88b36b ] - (SEMVER-MINOR) buffer : add end parameter (Robert Nagy) #62390 [ 1fefdda18e ] - crypto : update root certificates to NSS 3.125 (Node.js GitHub Bot) #64746 [ 4a158cf1ab ] - doc : add MikeMcC399 as collaborator (Mike McCready) #64656 [ d4cafce076 ] - (SEMVER-MINOR) lib,permission : add permission.drop (Rafael Gonzaga) #62672 [ b3cfb55267 ] - (SEMVER-MINOR) loader : implement package maps (Maël Nison) #62239 [ cd1eb3e60b ] - (SEMVER-MINOR) src,permission : add --permission-audit (RafaelGSS) #61869 [ 28dc85d8d2 ] - (SEMVER-MINOR) stream : add node:stream/iter implementation (James M Snell) #62066 [ d31c168740 ] - (SEMVER-MINOR) test_runner : add context.log() and test:log event (Moshe Atlow) #64389 [ add1edbc42 ] - (SEMVER-MINOR) test_runner : report entryFile in TestStream events (Moshe Atlow) #64309 [ d937c8c6cd ] - (SEMVER-MINOR) wasm : enable JSPI (Guy Bedford) #59941 Commits [ 1822c0f335 ] - assert,util : fix TypeError on Maps with null keys (Paul Bouchon) #64441 [ b12bcc9ae1 ] - (SEMVER-MINOR) async_hooks : add using scopes to AsyncLocalStorage (Stephen Belanger) #61674 [ 984260bf44 ] - async_hooks : use validateBoolean for trackPromises (Soul Lee) #64731 [ ba2612cca2 ] - benchmark : fix calibrate-n option handling (Luan Muniz) #64146 [ 236dc4d2d7 ] - benchmark : add bytes variant to webstreams async-iterator (Matteo Collina) #64291 [ b022a1419c ] - benchmark : respect stream/iter broadcast backpressure (Trivikram Kamat) #63314 [ a290f51f15 ] - (SEMVER-MINOR) benchmark : add benchmarks for experimental stream/iter (James M Snell) #62066 [ 465f2bfb74 ] - buffer : use Clamp conversion in Blob slice (Donghoon Kang) #64739 [ 74a22cd0c5 ] - buffer : validate copyArrayBuffer offsets against buffer length (Ilia Alshanetsky) #63904 [ 21e24208dc ] - buffer : normalize lone "\r" in Blob native line endings (Daijiro Wachi) #64115 [ ddacb3ff10 ] - buffer : fix Blob.stream() leaking source buffer (semimikoh) #63577 [ 49198d2313 ] - buffer : fix end parameter bugs in indexOf/lastIndexOf (Robert Nagy) #62711 [ e2eb88b36b ] - (SEMVER-MINOR) buffer : add end parameter (Robert Nagy) #62390 [ e2e5c4fe88 ] - build : update binary-upload to use correct tarball name (Stewart X Addison) #65282 [ b78a212553 ] - build : pin envinfo versions in github actions (Joyee Cheung) #64117 [ 094fb840aa ] - build : add QUIC CI job for PRs matching QUIC related paths (Tim Perry) #63875 [ 91f5003cad ] - build : fix flags for ngtcp2 on IBM i (SRAVANI GUNDEPALLI) #60073 [ e83648effd ] - build,test : add tests for binary linked with shared libnode (Joyee Cheung) #61463 [ 4a425b41d9 ] - build,tools : fix shared library cross-compile (Kirill Saied) #63963 [ fe8fa45ff2 ] - cli : style node --help output with util.styleText (Adrián Estrada) #64484 [ 3cd1576cb2 ] - crypto : preserve OpenSSL errors from KDF failures (Filip Skokan) #64776 [ 74b3023565 ] - crypto : handle XOF output allocation failure (Filip Skokan) #64851 [ fea0666a1b ] - crypto : clarify missing cipher error (Filip Skokan) #64852 [ 33fec91b54 ] - crypto : reuse X509 issuer result (Filip Skokan) #64852 [ 44c1473348 ] - crypto : validate key generation options (Filip Skokan) #64852 [ c2c53a18e5 ] - crypto : fix Argon2 validation errors (Filip Skokan) #64852 [ edc1f2126d ] - crypto : initialize KeyObjectData mutex eagerly (Filip Skokan) #64851 [ be8237240c ] - crypto : handle DH operation failures (Filip Skokan) #64851 [ b65a8f3875 ] - crypto : preserve RSA-PSS legacy pubkey DER (Filip Skokan) #64547 [ 49f2ae204b ] - crypto : cleanse provider private key copies (Filip Skokan) #64547 [ a5d4ac8208 ] - crypto : handle incomplete RSA private keys (Filip Skokan) #64547 [ b72c0b9616 ] - crypto : retain legacy DH validation (Filip Skokan) #64547 [ 24a1be5886 ] - crypto : limit KangarooTwelveParams customization to 512 bytes (Filip Skokan) #64557 [ 0290e0a61e ] - crypto : sp

Known issues

Publisher statement

Not stated. The verified publisher record does not contain a known-issues statement.

Affected products and versions

Products

  • Node.js

Affected versions

  • 24.20.0
  • 3.125

Fixed versions or updates

  • No fixed version is stated in this record.

Recommended action

Review the official publisher document before deployment.

These links connect the publisher update to related Lifecycle records without treating the update publication date as an end-of-support date.

Official publisher evidence

OPENJS FOUNDATIONVERIFIED

2026-08-26, Version 24.20.0 'Krypton' (LTS), @aduh95

Checked 28 Sep 2026. BlackTree preserves the last verified facts if a later source check is temporarily unavailable.

Open the official publisher source