Node.js @nodejs.org · Mar 25

With a security release deadline to meet, we interleaved the hash exploration, statistical evaluation, V8 implementation, and performance testing during the development. More details in the blog post.

3 likes 1 replies

?

Replies

Node.js · Mar 25

The fix has been merged into V8 and can be enabled via `v8_enable_seeded_array_index_hash`. It has been shipped to Node.js v25, v24, v22, and v20 via the March 2026 security release. Upgrade now to to protect your applications from this vulnerability!