# Updating Node.js (Ubuntu) within the Kibana application

**URL:** <https://discuss.elastic.co/t/updating-node-js-ubuntu-within-the-kibana-application/387720>\
**Category:** Kibana\
**Created:** [July 7, 2026, 2:59pm UTC](https://discuss.elastic.co/t/updating-node-js-ubuntu-within-the-kibana-application/387720 "2026-07-07T14:59:11Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![MandoStorm](https://avatars.discourse-cdn.com/v4/letter/m/67e7ee/32.png) [@MandoStorm](https://discuss.elastic.co/u/MandoStorm)\
**Post date:** [July 7, 2026, 2:59pm UTC](https://discuss.elastic.co/t/updating-node-js-ubuntu-within-the-kibana-application/387720/1 "2026-07-07T14:59:11Z")

</div>

Good morning/afternoon,

I am currently running Ubuntu 24.04 and I want to upgrade the version of node.js to v26.3.1 within kibana application. Any guidance would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 7, 2026, 3:10pm UTC](https://discuss.elastic.co/t/updating-node-js-ubuntu-within-the-kibana-application/387720/2 "2026-07-07T15:10:03Z")

</div>

Hello and welcome,

> [@MandoStorm](#):
>
> I am currently running Ubuntu 24.04 and I want to upgrade the version of node.js to v26.3.1 within kibana application.

You cannot upgrade Node directly, you need to upgrade Kibana and the rest of the stack.

Which version are you?

---

<div class="post-metadata">

**Author:** ![MandoStorm](https://avatars.discourse-cdn.com/v4/letter/m/67e7ee/32.png) [@MandoStorm](https://discuss.elastic.co/u/MandoStorm)\
**Post date:** [July 7, 2026, 3:30pm UTC](https://discuss.elastic.co/t/updating-node-js-ubuntu-within-the-kibana-application/387720/3 "2026-07-07T15:30:44Z")

</div>

Good morning Leandro,

The version Elastic Kibana is 9.4.2.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 7, 2026, 3:40pm UTC](https://discuss.elastic.co/t/updating-node-js-ubuntu-within-the-kibana-application/387720/4 "2026-07-07T15:40:32Z")

</div>

Kibana 9.X still uses Node v24, 9.4.2 and 9.4.3 uses 24.14.1.

Version 9.5.0 (not released yet) seems to bump it to 24.18.0

Why you need version 26.3.1? Any security tool complaining about the version?

---

<div class="post-metadata">

**Author:** ![Wakizu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wakizu/32/147851_2.png) [@Wakizu](https://discuss.elastic.co/u/Wakizu)\
**Post date:** [July 9, 2026, 5:12pm UTC](https://discuss.elastic.co/t/updating-node-js-ubuntu-within-the-kibana-application/387720/5 "2026-07-09T17:12:56Z")

</div>

same situation for me too . auditor flagged kibana 8.19.17 with node 22.22.2

CVE-2026-48617 Critical 10.10.x.x Node.js 22.x \< 22.23.0 / 24.x \< 24.17.0 / 26.x \< 26.3.1 Multiple Vulnerabilities (Thursday, June 18, 2026 Security Releases). The version of Node.js installed on the remote host is prior to 22.23.0, 24.17.0, or 26.3.1. It is, therefore,  
affected by multiple vulnerabilities as referenced in the Thursday, June 18, 2026 Security Releases advisory.

- A flaw in Node.js WebCrypto implementation can crash the process if the input of subtle.encrypt() is a  
multiple of 2GiB. (CVE-2026-48933)

- A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls  
wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismatch.  
(CVE-2026-48618)

- A flaw in Node.js proxy tunnel error handling could expose proxy credentials in ERR\_PROXY\_TUNNEL error  
messages. When proxy credentials are embedded in the proxy URL, they may be exposed through error handling  
paths and captured by logs, diagnostics, or other error consumers. (CVE-2026-48615)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version  
number. Upgrade to Node.js version 22.23.0 / 24.17.0 / 26.3.1 or later.   
Path : /usr/share/kibana-8.19.17/node/glibc-217/bin/node  
Installed version : 22.22.2  
Fixed version : 22.23.0
