Node.js 18 End of Life: Which Vendors Offer Extended Security Support?
Node.js 18 is end of life. It has not received security patches since April 30, 2025. Any CVE disclosed after that date is a permanent unpatched vulnerability in your production environment. Organizations running Node.js 18 need either a migration plan or a commercial extended support contract — now.
Key Dates at a Glance
- Node.js 24: active support ends 2026-10-20; end of life 2028-04-30
- Node.js 22: active support ends 2025-10-21; end of life 2027-04-30
- Node.js 18: active support ends 2023-10-18; end of life 2025-04-30
- Node.js 12: active support ends 2020-10-20; end of life 2022-04-30
- Node.js 7: end of life 2017-06-30
- Node.js 6: active support ends 2018-04-30; end of life 2019-04-30
Node.js 18 lifecycle timeline
Node.js 18 entered its Active LTS phase in October 2022 and moved to security-maintenance-only in October 2023. The OpenJS Foundation ended all support on April 30, 2025. No further patches will be released for any CVE, regardless of severity.
Which vendors offer extended CVE patches for Node.js 18?
Several commercial vendors have built extended lifecycle support programs specifically for EOL Node.js versions. Here is a comparison of the main options available as of 2026:
Third-Party ELS Vendors
Extended Lifecycle SupportSpecialist ELS vendors cover Node.js runtimes as part of their open-source extended support offerings. Multi-year contracts available, typically covering CVSS 7+ vulnerabilities.
View via endoflife.ai →Feature comparison
| Vendor | CVE patching | Compliance docs | Multi-year contracts | Other EOL runtimes |
|---|---|---|---|---|
| Third-party ELS vendors | ✓ CVSS 7+ | ✓ | ✓ | Linux, PHP, Python |
Migrate or extend? How to decide
Choose migration if your Node.js 18 application can be moved to Node.js 22 LTS within 6–12 months without major breaking changes. Node.js 22 is supported until April 2027 and Node.js 24 entered LTS in 2025. Migration eliminates ongoing support costs.
Choose extended support if migration is blocked by: third-party dependency incompatibilities, regulatory change-freeze periods, insufficient engineering bandwidth, or complex monorepos where upgrading the runtime requires months of testing.
ELS is a bridge — not a destination. The right answer is always to establish a migration timeline alongside any extended support contract.
Check your full EOL exposure
See which vendors cover every EOL component in your stack — not just Node.js 18.
Open CVE Intelligence Tool →Node.js currently carries an EOL Risk Score™ of 55/100 — Grade C, elevated risk, recalculated at every site build from EOL recency, attack surface, CISA KEV exposure, and extended-support availability. Per-version scores and dates are on the Node.js lifecycle page.
The right response comes down to one question: how many more years does this system need to run? Under a year, extended support (where it exists) is usually cheaper than an emergency migration. One to three years, migrate — support fees paid repeatedly cost more than doing the project once. Indefinitely, migrate now and plan the next one before it surprises you. Extended support is often the more expensive choice over a multi-year horizon — a bridge, not a destination. And if this deadline feels like vendor caprice, it isn’t — why end of life is inevitable for every version, with the receipts.
Frequently asked questions
The Monthly EOL Digest™
Once a month — critical EOL dates, CVE blind spots, and lifecycle changes worth knowing about.