end-of-life.org

Node.js 0.12 End of Life

Support dates, vulnerabilities published since end of life, and upgrade guidance — rebuilt from live data.

End of Life

Node.js 0.12 reached end of life on 31 Dec 2016. It no longer receives security fixes.

3,565 days without security patches
160 Node.js CVEs published since EOL
Recommended action: upgrade to Node.js 27.
Check your versionnode --version

Support timeline

Official dates, read directly from github.com and nodejs.org.

MilestoneDateStatus
Initial release6 Feb 2015 11y 8mo ago
Security Support ended31 Dec 2016 9y 9mo ago
Latest release— final

The cost of staying: CVEs since end of life

160 Node.js vulnerabilities have been published since 31 Dec 2016. All were fixed in supported branches — 0.12 received none of them. Source: NVD.

Node.js CVEs published since 0.12's EOL, by year

15 of the 160 are rated critical · data refreshed 2026-10-05

0 15 30 24 2017 20 2018 11 2019 14 2020 16 2021 17 2022 21 2023 6 2024 1 2025 30 2026
CVE-2026-21636 CVSS 10

Published 20 Jan 2026 · rated critical — fixed in supported branches only, never in 0.12. Details

CVE-2016-9841 CVSS 9.8

Published 23 May 2017 · rated critical — fixed in supported branches only, never in 0.12. Details

CVE-2016-9843 CVSS 9.8

Published 23 May 2017 · rated critical — fixed in supported branches only, never in 0.12. Details

Where to go from 0.12

Recommended target: Node.js 27 (supported until 30 Apr 2030).

The newest actively supported branch is Node.js 27 (latest release ). Review the Node.js changelog before upgrading. Run npx ls-engines to check package compatibility.

Frequently asked questions

Is Node.js 0.12 still safe to use?

No. Node.js 0.12 stopped receiving security fixes on 31 Dec 2016. Since then, 160 Node.js vulnerabilities have been published and fixed in supported branches — Node.js 0.12 received none of those fixes.

Can I still download Node.js 0.12?

Yes — the final release (0.12) generally remains available from vendor archives and OS package mirrors, but installing it means running software with known, unpatched vulnerabilities.

What should I upgrade Node.js 0.12 to?

Upgrade to Node.js 27, the newest actively supported branch (supported until 30 Apr 2030).

All Node.js versions