When Node.js versions go end-of-life, the CVEs don’t stop.

Supported Versions: 12, 14, 16, 18, 20

Never-Ending Support for Node.js gives your security team, your engineers, and your leadership back something they lost at EOL: the power to control their own security posture, their own timeline, and where the business focuses its attention.

TRUSTED BY ENTERPRISE

Google logoMicrosoft logoFinra logoBank Santander Logo
Hitachi LogoWorkday logoDropbox logo

BACKED BY CORE CONTRIBUTORS

OpenJS Foundation logo

Partner

Security, compliance, and continuity -- solved together

With our secure drop-in replacement for end-of-life versions of Node.js, your scanners stop flagging CVEs in end-of-life Node.js versions for good.

Security Patches

CVE fixes for all severity levels on end-of-life versions of  Node.js  —  closing the window attackers depend on.

SLA-backed patch delivery tied to severity

Remediation and back-porting fixes for all EOL versions

Fleet-wide coverage, cloud & on-prem

Compliance

With NES, your scanners stop flagging CVEs in end-of-life Node.js versions — turning open audit findings into closed ones.

Coverage for SOC 2, PCI DSS, HIPAA, FedRAMP, DORA, NIS2, among other standards, frameworks, and regulations

DORA, NIS2, EU Cyber Resilience Act, and more

Meet internal policies and customer compliance requirements

Business Continuity

A drop-in replacement that installs in seconds with no app code changes — so you migrate on your own schedule with the runtime secure.

Months or years of runway to migrate right

No rewrites, no broken builds

A fraction of migration cost

Use cases from the day you install Never-Ending Support

Before — the pain

Hundreds of services stuck on EOL Node.js

Scanners flag every run, no upstream patches are coming, and when a new CVE drops the window between disclosure and exploit is wide open.

After — with HeroDevs

The fleet moves from exposed to defended

NES drops in across on-prem or cloud (AWS, Azure, GCP) services with no code changes. SLA-backed CVE patches resume on versions 12–20.

Before — the pain

An open finding with no answer

Internal audit, SOC 2, and a customer security questionnaire all flag EOL Node.js. There's no remediation path, and leaders have no defensible answer for auditors or the board.

After — with HeroDevs

Findings close, questionnaires answer themselves

Commercial support with committed SLAs and OpenJS Foundation endorsement. Scanners stop flagging CVEs and you reference a named, vendor-backed runtime aligned to PCI DSS, HIPAA, SOC 2, DORA, NIS2, and CRA.

Before — the pain

The EOL clock vs. the roadmap

The backlog is full, headcount is frozen, and cloud providers are deprecating EOL runtimes. A rushed migration across hundreds of services risks production incidents and pulls engineers off the roadmap.

After — with HeroDevs

Migrate on your terms, not the clock

A drop-in across the fleet — no code changes, on-prem or cloud. Teams get 1–3 years of breathing room to plan a proper migration while the runtime stays secure, compliant, and stable.

By leveraging HeroDevs' extended support, we were able to mitigate security risks, continue safe operation of the legacy application, and gain valuable time to plan a more sustainable long-term migration strategy—all without compromising on client experience or regulatory requirements.

— Sanlam Private Wealth

Every patch we ship has a published CVE entry

HeroDevs is an authorized CVE Numbering Authority (CNA), empowered by the CVE Program to discover and assign CVE IDs to security vulnerabilities discovered by HeroDevs.

If you're running EOL Node.js today, your applications are exposed to the vulnerabilities below. Switch to NES in minutes to mitigate them. Every fix is published, one CVE per entry.
Severity
CVE
Category
Version(s) Affected
Published Date
Medium
Improper Input Validation (4.16)
>=0.16.0 <2.0.10 >=3.0.0 <3.0.6 >=4.0.0 <4.1.0
Jul 14, 2026
Medium
Denial of Service
<20.20.2 >=22.0.0 <22.22.2 >=24.0.0 <24.14.1 >=25.0.0 <25.8.2
Apr 13, 2026
High
Uncontrolled Resource Consumption
v4 < v20.20.0, v22 < v22.22.0, v24 < v24.13.0, v25 < v25.3.0
Jan 13, 2026
High
Path Traversal
4.0 < 20.19.4, 22 < 22.17.1, 24 < 24.4.1
Jul 15, 2025
Medium
HTTP Request Smuggling
4.0 < 20.19.1
May 14, 2025
High
Cryptographic Weakness
4.0 < 20.19.1, 22 < 22.15.0, 24 < 24.0.1
May 14, 2025
Medium
Denial of Service
4.0 < 18.20.6, 20 < 20.18.2
Feb 7, 2025
Medium
Path Traversal
4.0 < 18.20.6, 20 < 20.18.2
Jan 28, 2025
High
Command Injection
4.0 <= 18.20.2, 20 < 20.12.2
Jan 9, 2025
High
HTTP Request Smuggling
>=16.0.0 <16.20.1, >=18.0.0 <18.16.1, >=20.0.0 <20.3.1
Oct 16, 2024
Low
Information Exposure
>=16.0.0 <=16.20.2
Oct 15, 2024
Medium
Denial of Service
>=14.0.0 <=14.21.3, >=16.0.0 <=16.20.2
Oct 15, 2024
Medium
Cryptographic Weakness
4.0 < 18.19.1, 20 < 20.11.1
Sep 7, 2024
High
Command Injection
4.0 < 18.20.4, 20.0 < 20.15.1, 22.0< 22.4.1
Sep 7, 2024
Medium
HTTP Request Smuggling
4.0 < 18.20.1, 20 < 20.12.1
May 7, 2024
Medium
HTTP Request Smuggling
<21.7.2, <20.12.1, <v18.20.1, <= 16.20.2, <=v14.21.3, <= v12.22.12
May 1, 2024
High
Uncontrolled Resource Consumption
4 <= 18.20.0, 20 <= 20.12.0
Apr 9, 2024
High
Privilege Escalation
4.0 < 18.19.1, 20 < 20.11.1
Feb 20, 2024
Medium
Denial of Service
<21.6.2, <20.11.1, <v18.19.1, <= 16.20.2
Feb 14, 2024
High
Denial of Service
<21.6.2, <20.11.1, <v18.19.1, <= 16.20.2, <=v14.21.3, <= v12.22.12
Feb 14, 2024
Medium
Cryptographic Weakness
4.0 < 16.20.1, 18 < 18.16.1, 20 < 20.3.1
Nov 28, 2023
Medium
Insufficient Verification of Data Authenticity
4.0 <= 18.18.1, 20 < 20.8.1
Oct 18, 2023
Medium
Privilege Escalation
4 <= 16.20.1, 0 <= 18.17.0, 0 <= 20.5.0
Aug 24, 2023
Medium
HTTP Request Smuggling
4.0 < 16.20.1, 18 < 18.16.1, 20 < 20.3.1
Jun 30, 2023
Medium
HTTP Request Smuggling
4.0 < 14.20.1, 16 < 16.17.1, 18 < 18.9.1
Dec 5, 2022
High
Resource Injection
4.0 < 14.20.0, 16 < 16.20.0, 18 < 18.5.0
Jul 14, 2022
Medium
HTTP Request Smuggling
4.0 < 14.20.1, 16 < 16.17.1, 18 < 18.9.1
Jul 14, 2022
High
Authorization Bypass
4.0 < 14.20.1, 16 < 16.17.1, 18 < 18.9.1
Jul 14, 2022
Medium
HTTP Request Smuggling
4.0 < 14.20.0, 16 < 16.20.0, 18 < 18.5.0
Jul 14, 2022
Medium
HTTP Request Smuggling
4.0 < 14.20.1, 16 < 16.17.1, 18 < 18.9.1
Jul 14, 2022

0 CVEs remediated -- and counting

See Full Directory
Filtering by:
Severity
=
Text for Severity
Close icon
Clear Filters
Severity
ID
Category
Version(s) Affected
Published Date
Medium
Cryptographic Weakness
4.0 < 16.20.1, 18 < 18.16.1, 20 < 20.3.1
Nov 28, 2023
Medium
Insufficient Verification of Data Authenticity
4.0 <= 18.18.1, 20 < 20.8.1
Oct 18, 2023
Medium
Privilege Escalation
4 <= 16.20.1, 0 <= 18.17.0, 0 <= 20.5.0
Aug 24, 2023
Medium
HTTP Request Smuggling
4.0 < 16.20.1, 18 < 18.16.1, 20 < 20.3.1
Jun 30, 2023
Medium
HTTP Request Smuggling
4.0 < 14.20.1, 16 < 16.17.1, 18 < 18.9.1
Dec 5, 2022
High
Resource Injection
4.0 < 14.20.0, 16 < 16.20.0, 18 < 18.5.0
Jul 14, 2022
Medium
HTTP Request Smuggling
4.0 < 14.20.1, 16 < 16.17.1, 18 < 18.9.1
Jul 14, 2022
High
Authorization Bypass
4.0 < 14.20.1, 16 < 16.17.1, 18 < 18.9.1
Jul 14, 2022
Medium
HTTP Request Smuggling
4.0 < 14.20.0, 16 < 16.20.0, 18 < 18.5.0
Jul 14, 2022
Medium
HTTP Request Smuggling
4.0 < 14.20.1, 16 < 16.17.1, 18 < 18.9.1
Jul 14, 2022

Easy to deploy, No disruptions.

Install NES for Node.js
$export NVM_NODEJS_ORG_MIRROR= https://registry.nes.herodevs.com/nodejs/nes
$export NVM_AUTH_HEADER="Bearer <token>"
$nvm install v18.20.6-nes
Downloading and installing node v18.20.6-nes...
Now using node v18.20.6-nes (npm v10.8.2) ✓
1

Pick your version

Available in HeroDevs NES registry. NES Node.js versions  12, 14, 16, 18, or 20.

2

Set up your token

Add your HeroDevs auth token so your environment can pull the patched runtime securely.

3

Drop it in

Install the NES version. No application code changes. Container image or binary available.

4

Scanners pass

Actively patched and commercially supported — so CVE findings on EOL Node.js close.

Deploy across every cloud -- and on-prem.

NES for Node.js ships as container images and binaries, so the same SLA-backed patches reach every service you run -- from serverless functions to Kubernetes, to bare VMs on AWS, Azure, Google Cloud, and on-premises.

Amazon Web Services logo

Amazon Web Services

AWS Lambda

Amazon EC2

AWS Fargate

AWS App Runner

Amazon ECS

Microsoft Azure logo

Microsoft Azure

Azure App Service

Azure Functions

Azure Kubernetes Services (AKS)

Azure Virtual MachinesAzure Virtual Machines

Azure Static Web Apps

Azure Batch

Google Cloud logo

Google Cloud

Cloud Run

Cloud Run Functions

Google App Engine (GAE)

Google Kubernetes Engine (GKE)

Google Compute Engine (GCE)

Cloud Run Jobs

Built by the people who built Node.js

We Partner With Core Contributors

We collaborate with the Node.js project to ensure NES is the same quality you expect. By involving core maintainers, we set a new standard for sunsetted open source to make NES as dependable as the original.

Vue LogoAngular LogoDrupal Association logoNuxt LogoProtractor logo
OpenJS Foundation logo
HeroDevs logo

Founding member of the OpenJS Foundation's Ecosystem Sustainability Program (ESP) and Gold Member of the OpenJS Foundation. NES for Node.js, ESLint, and other OpenJS projects.

Learn More →
User icon wiht computer

We Give Back to Open Source

Open source maintainers do critical work, but rarely get paid for it.

HeroDevs is putting $20 million toward changing that — funding the creators and projects that keep the ecosystem running, with grants from $2,500 to $250,000.

We’ve written patches for unmaintained codebases, tracked down vulnerabilities where no one else was looking, and kept critical systems running safely without rushed rewrites. This fund builds on that work, so maintainers can keep doing what they do best.

Why organizations choose NES for Node.js

NES for Node.js is the only EOL Node.js support endorsed by the OpenJS Foundation and built with Node.js core-maintainer expertise — and HeroDevs funds and supports the open source community directly. Most alternatives can't say the same.

Others
Endorsed by the OpenJS Foundation and Founding Ecosystem Sustainability Program (ESP) Member
Not endorsed
Built with Node.js core-maintainer expertise. Employs TSC members
CVE Numbering Authority (CNA)
Drop-in replacement, no code changes
Multi-platfrom and cloud services support  (AWS, Azure, GCP)
Accurate public CVE directory of EOL fixes
SLA-backed patches & compliance evidence
Third-party back porting often (AI-driven)
No vulnerability discovery, not a CNA
Varies, mainly binary
Often Linux distribution focused
Unclear and inaccurate tracking of CVEs and fixes
Varies by vendor
HeroDevs logo
The only OpenJS-endorsed EOL support
Yes
Discovery and publication of CVEs
Container image or binary
All major cloud services, containers, Linux, and Windows
One entry per fixed CVE
SLA + documented patch history

A defensible answer for every standard, framework, or regulation

EOL software undermines patch-management expectations across regulations worldwide. NES gives you a maintained, vendor-backed runtime with committed SLAs and a documented patch history to demonstrate to auditors and regulators full compliance with those requirements.

PCI DSS

US

Req. 6.3.3 requires known critical or high-severity vulnerabilities be patched within 30 days. EOL Node.js with no patch means immediate non-compliance — NES restores the patch path.

HIPAA

US

Unsupported runtimes make it hard to show reasonable safeguards for systems handling ePHI. NES provides active maintenance and risk reduction.

SOC 2

Global

Trust Services Criteria expect timely vulnerability remediation and patch management. EOL runtimes fail certification without support.

NIS2

EU

Article 21 covers patching, vulnerability and supply-chain management. EOL software is effectively non-compliant where it creates risk.

DORA

EU

Treats EOL software as a resilience flaw for financial ICT assets. NES sustains a documented patch-management program.

Cyber Resilience Act

EU

Governs software lifecycle security. NES keeps the runtime handled effectively during the support period.

NIST CSF 2.0

US

NIST CSF control PR.PS-02 requires organizations to actively maintain or remove vulnerable software based on risk. NES enables compliance without forced upgrade or removal.

FedRAMP

US

Continuous monitoring expects flaw remediation on a defined cadence. A patched, vendor-backed runtime keeps EOL Node.js inside the boundary.

Commercial Contracts

Global

Many organizations are contractually prohibited from shipping unsupported software. NES provides the vendor-backed answer your own policies require.

ISO/IEC 27001:2022

Global

Vulnerability Management and Configuration Management controls require identifying technical vulnerabilities and keeping software within secure standards. NES restores control posture with patch availability for EOL software.

NIST SP 800-171

US

Mandatory for DoD contractors and suppliers handling Controlled Unclassified Information (CUI). It requires identifying, reporting, and correcting system flaws, including vulnerabilities. NES provides that for EOL software.

CIS Controls

Global

Control 7 (Continuous Vulnerability Management) and Control 2 (Software Asset Inventory) treat software that no longer receives security updates as inherently vulnerable. NES keeps EOL runtimes patched and auditable.

Frequently Asked Questions

Does HeroDevs have an SLA for NES for Node.js?
What Node.js versions does NES support?
Does NES for Node.js help with compliance?
Why do I need NES for Node.js?
How does licensing work?
I got an error like "EOL/Obsolete Software: Node.js 12.x Detected." What can I do?

Contact Us

Got questions about Never-Ending Support for your open-source library? We're here to help!

Discover how HeroDevs NES Products can keep your systems secure and compliant.

Learn how our solutions can deliver value to your organization.

Get detailed pricing information tailored to your needs.

Google logoLilly logoAbbott logoBox logoEG logoHitachi logoDropbox logoNHS logoWorkday logoFinra logoMicrosoft logoSantander logo
Talk to an Expert

By submitting the form I acknowledge receipt of our Privacy Policy.

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.