Node.js 5 End of Life
Support dates, vulnerabilities published since end of life, and upgrade guidance — rebuilt from live data.
Node.js 5 reached end of life on 30 Jun 2016. It no longer receives security fixes.
Support timeline
Official dates from the Node.js release process.
| Milestone | Date | Status |
|---|---|---|
| Initial release | 30 Oct 2015 | — |
| End of life | 30 Jun 2016 | 10.1 years ago |
| Latest release | 5.12.0 · 23 Jun 2016 | final |
The cost of staying: CVEs since end of life
157 Node.js vulnerabilities have been published since 30 Jun 2016. All were fixed in supported branches — 5 received none of them. Source: NVD.
Node.js CVEs published since 5's EOL, by year
17 of the 157 are rated critical · data refreshed 2026-08-09
Published 20 Jan 2026 · rated critical — fixed in supported branches only, never in 5. Details
Published 16 Sept 2016 · rated critical — fixed in supported branches only, never in 5. Details
Published 3 Oct 2016 · rated critical — fixed in supported branches only, never in 5. Details
Where to go from 5
Recommended target: Node.js 26 (supported until 30 Apr 2029).
The newest actively supported branch is Node.js 26 (latest release 26.7.0). Review the Node.js changelog before upgrading. Run npx ls-engines to check package compatibility.
Frequently asked questions
Is Node.js 5 still safe to use?
No. Node.js 5 stopped receiving security fixes on 30 Jun 2016. Since then, 157 Node.js vulnerabilities have been published and fixed in supported branches — Node.js 5 received none of those fixes.
Can I still download Node.js 5?
Yes — the final release (5.12.0) generally remains available from vendor archives and OS package mirrors, but installing it means running software with known, unpatched vulnerabilities.
What should I upgrade Node.js 5 to?
Upgrade to Node.js 26, the newest actively supported branch (supported until 30 Apr 2029).