NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #262 most downloaded on npm
Fast, unopinionated, minimalist web framework
Last release 20 days ago
14 Sep 2026
Release timing varies
gaps range from 3 weeks to 1.4 years
Nearly every release is documented
notes for 60 of the last 60 stable releases
173 versions withdrawn
withdrawn after publishing
16 years old
289 releases · first in 2010
There is no actual security vulnerability associated with this behavior ( CVE-2024-51999 has been rejected). The change has been fully reverted in thi…
Important
The prior release (5.2.0) included an erroneous breaking change related to the extended query parser. There is no actual security vulnerability associated with this behavior (CVE-2024-51999 has been rejected). The change has been fully reverted in this release.
Full Changelog: v5.2.0...v5.2.1
Security fix for CVE-2024-51999 ( GHSA-pj86-cfqh-vqx6 )
One column per quarter.
acceptsLanguages implementation using spread operator by @Ayoub-Mabrouk in #6137Buffer import and add lint rule by @shivarm in #6525Full Changelog: v5.1.0...v5.2.0
fix(securite): fix vulnerabilities by @Abdel-Monaam-Aouini in #6211
methods dependency with standard library by @jonkoops in #6196utils-merge dependency - use spread syntax instead by @Phillip9587 in #6091depd dependency by @jonkoops in #6197Invalid action input 'persist-credentials' for actions/setup-node@v4 in ci.yml by @hamirmahal in #6256normalizeTypes function by @Ayoub-Mabrouk in #6097debug to ^4.4.0 by @Phillip9587 in #6313https instead of http by @Phillip9587 in #6338Full Changelog: 5.0.1...v5.1.0
Update cookie semver lock to address CVE-2024-47764 by @joshbuker in https://github.com/expressjs/express/pull/6017
cookie semver lock to address CVE-2024-47764 by @joshbuker in https://github.com/expressjs/express/pull/6017Full Changelog: https://github.com/expressjs/express/compare/v5.0.0...5.0.1
cookie semver lock to address CVE-2024-47764 by @joshbuker in #6017Full Changelog: v5.0.0...5.0.1
This release includes important security fixes, including improvements to prevent ReDoS attacks and mitigation for CVE-2024-45590. Full details can be…
🎉 Express v5 is finally here! 🎉
After years of development, the long-awaited Express v5 has been officially released. This version focuses on simplifying the codebase, improving security, and dropping support for older Node.js versions to enable better performance and maintainability.
For detailed information, please check out the official Express v5 release blog post.
path-to-regexp@8.x, removing sub-expression regex patterns for security reasons (ReDoS mitigation).body-parser changes: Several improvements including the ability to customize urlencoded body depth and defaulting extended to false.For a complete list of breaking changes and API deprecations, see the migration guide.
This release includes important security fixes, including improvements to prevent ReDoS attacks and mitigation for CVE-2024-45590. Full details can be found in the security release notes.
Be sure to check out our migration guide for instructions on how to update your applications from Express v4 to v5.
For best practices, we recommend reviewing the Threat Model which outlines Express' approach to securing your applications, including tips for user input validation and other critical aspects.
http-errors, expressjs.com, morgan, cors, body-parser by @jonchurch in https://github.com/expressjs/express/pull/5587res.clearCookie accepting options.maxAge and options.expires by @jonchurch in https://github.com/expressjs/express/pull/5672expires and maxAge in res.clearCookie() by @jonchurch in https://github.com/expressjs/express/pull/5792debug dep from 3.10 to 4.3.6 by @carpasse in https://github.com/expressjs/express/pull/5829question and discuss by @IamLizu in https://github.com/expressjs/express/pull/5835merge-descriptors with allowing minors by @RobinTail in https://github.com/expressjs/express/pull/5782merge-descriptors dependency by @RobinTail in https://github.com/expressjs/express/pull/5781fresh@^2.0.0 by @jonchurch in https://github.com/expressjs/express/pull/5916back as a magic string by @blakeembrey in https://github.com/expressjs/express/pull/5933Full Changelog: https://github.com/expressjs/express/compare/v5.0.0-beta.3...v5.0.0
Full Changelog: https://github.com/expressjs/express/compare/5.0.0-beta.2...v5.0.0-beta.3
Full Changelog: https://github.com/expressjs/express/compare/5.0.0-beta.2...v5.0.0-beta.3
Replace deprecated String.prototype.substr() by @CommanderRoot in https://github.com/expressjs/express/pull/4860
obj as the context by @shesek in https://github.com/expressjs/express/pull/3587maxAge appropriateness before use by @cjbarth in https://github.com/expressjs/express/pull/3936Full Changelog: https://github.com/expressjs/express/compare/v5.0.0-beta.1...5.0.0-beta.2
This is the first Express 5.0 beta release, based off 4.17.2 and includes changes from 5.0.0-alpha.8.
This is the first Express 5.0 beta release, based off 4.17.2 and includes changes from 5.0.0-alpha.8.
'simple'mime-types for file to content type mappingreq.body is no longer always initialized to {}urlencoded parser now defaults extended to falseon-finished to determine when body read?, *, and + parameter modifiersrouter.process_params methodreq.paramsdebug dependency* path segment behavior removeddotfiles option default to 'ignore'hidden option; use dotfiles option insteadmime-types for file to content type mappingdotfiles option default to 'ignore'hidden option; use dotfiles option insteadmime-types for file to content type mappingThis is the sixth Express 5.0 alpha release, based off 4.17.1 and includes changes from 5.0.0-alpha.7.
This is the sixth Express 5.0 alpha release, based off 4.17.1 and includes changes from 5.0.0-alpha.7.
This is the seventh Express 5.0 alpha release, based off 4.16.4 and includes changes from 5.0.0-alpha.6.
This is the seventh Express 5.0 alpha release, based off 4.16.4 and includes changes from 5.0.0-alpha.6.
The major change with this alpha is the basic support for returned, rejected Promises in the router.
path-to-regexp dependencyDEBUG_HIDE_DATE environment variableDEBUG_FD environment variable supportRouter constructorThis is the sixth Express 5.0 alpha release, based off 4.15.5 and includes changes from 5.0.0-alpha.5.
This is the sixth Express 5.0 alpha release, based off 4.15.5 and includes changes from 5.0.0-alpha.5.
res.redirect(url, status) signature - use res.redirect(status, url)res.send(status, body) signature - use res.status(status).send(body)This is the fifth Express 5.0 alpha release, based off 4.15.2 and includes changes from 5.0.0-alpha.4.
This is the fifth Express 5.0 alpha release, based off 4.15.2 and includes changes from 5.0.0-alpha.4.
This is the fourth Express 5.0 alpha release, based off 4.15.0 and includes changes from 5.0.0-alpha.3.
This is the fourth Express 5.0 alpha release, based off 4.15.0 and includes changes from 5.0.0-alpha.3.
next("router") to exit from routerrouter.use skipped requests routes did notreq.url is not set%o in path debug to tell types apart* routeThis is the third Express 5.0 alpha release, based off 4.14.1 and includes changes from 5.0.0-alpha.2.
This is the third Express 5.0 alpha release, based off 4.14.1 and includes changes from 5.0.0-alpha.2.
res.json(status, obj) signature - use res.status(status).json(obj)res.jsonp(status, obj) signature - use res.status(status).jsonp(obj)res.vary() (no arguments) -- provide a field name as an argumentThis is the second Express 5.0 alpha release, based off 4.13.1 and includes changes from 5.0.0-alpha.1.
This is the second Express 5.0 alpha release, based off 4.13.1 and includes changes from 5.0.0-alpha.1.
app.param(fn)req.param() -- use req.params, req.body, or req.query insteadres.render callback is always async, even for sync view engines: character in name for app.param(name, fn) is no longer removedrouter module for routingpath-is-absolute module for absolute path detectionreq.acceptsCharset - use req.acceptsCharsets
app.del - use app.deletereq.acceptsCharset - use req.acceptsCharsetsreq.acceptsEncoding - use req.acceptsEncodingsreq.acceptsLanguage - use req.acceptsLanguagesres.json(obj, status) signature - use res.json(status, obj)res.jsonp(obj, status) signature - use res.jsonp(status, obj)res.send(body, status) signature - use res.send(status, body)res.send(status) signature - use res.sendStatus(status)res.sendfile - use res.sendFile insteadexpress.query middlewarereq.host now returns host (hostname:port) - use req.hostname for only hostnamereq.query is now a getter instead of a plain propertyapp.router is a reference to the base routerUpdate path-to-regexp to 0.1.13 to fix CVE-2026-4867 by @baryman in #7135
Full Changelog: v4.22.2...v4.22.3
fix: restore >20 array parsing for req.query repeated keys
req.query repeated keys (8d09bfe6)
a[0]=...) was historically capped at qs's default arrayLimit of 20 even in older qs versions; after this change it also allows up to 1000 items.Full Changelog: v4.22.1...v4.22.2
There is no actual security vulnerability associated with this behavior ( CVE-2024-51999 has been rejected). The change has been fully reverted in thi…
Important
The prior release (4.22.0) included an erroneous breaking change related to the extended query parser. There is no actual security vulnerability associated with this behavior (CVE-2024-51999 has been rejected). The change has been fully reverted in this release.
Full Changelog: 4.22.0...v4.22.1
Security fix for CVE-2024-51999 ( GHSA-pj86-cfqh-vqx6 )
npm i steps to fix ci for older node versions by @Phillip9587 in #6336qs by @Phillip9587 in #6919Full Changelog: 4.21.2...4.22.0
Add funding field (v4) by @bjohansebas in #6065
Full Changelog: 4.21.1...4.21.2
Backport a fix for CVE-2024-47764 to the 4.x branch by @joshbuker in #6029
Full Changelog: 4.21.0...4.21.1
Deprecate "back" magic string in redirects by @blakeembrey in #5935
"back" magic string in redirects by @blakeembrey in #5935Full Changelog: 4.20.0...4.21.0
[v4] Deprecate res.clearCookie accepting options.maxAge and options.expires by @jonchurch in https://github.com/expressjs/express/pull/5672
depth level for parsing URL-encoded data is now 32 (previously was Infinity)res.redirecthttp-errors, expressjs.com, morgan, cors, body-parser by @jonchurch in https://github.com/expressjs/express/pull/5587res.clearCookie accepting options.maxAge and options.expires by @jonchurch in https://github.com/expressjs/express/pull/5672question and discuss by @IamLizu in https://github.com/expressjs/express/pull/5835merge-descriptors dependency by @RobinTail in https://github.com/expressjs/express/pull/5781Full Changelog: https://github.com/expressjs/express/compare/4.19.1...4.20.0
Improved fix for open redirect allow list bypass
Full Changelog: https://github.com/expressjs/express/compare/4.19.1...4.19.2
Fix ci after location patch by @wesleytodd in https://github.com/expressjs/express/pull/5552
Full Changelog: https://github.com/expressjs/express/compare/4.19.0...4.19.1
fix typo in release date by @UlisesGascon in https://github.com/expressjs/express/pull/5527
Full Changelog: https://github.com/expressjs/express/compare/4.18.3...4.19.0
Use https: protocol instead of deprecated git: protocol by @vcsjones in https://github.com/expressjs/express/pull/5032
Full Changelog: https://github.com/expressjs/express/compare/4.18.2...4.18.3
Fix regression routing a large stack in a single route
Fix hanging on large stack of sync routes
Deprecate string and non-integer arguments to res.status
res.download
options without filename in res.downloadres.statusnull/undefined as maxAge in res.cookieObject.prototype values in settings through app.set/app.getdefault with same arguments as types in res.formatres.sendhttp-errors for res.format errorstrictpriority optionexpires option to reject invalid dateseval usage with Function constructorprocess to check for listeners425 Unordered Collection to standard 425 Too Earlypref: remove unnecessary regexp for trust proxy
__proto__ keysFix res.jsonp(obj, status) deprecation message
undefined in res.jsonp
undefined when "json escape" is enabledRegExpsres.jsonp(obj, status) deprecation messageres.is JSDocmaxAge option to reject invalid valuesreq.socket over deprecated req.connectionRevert "Improve error message for null/undefined to res.status"
null/undefined to res.status"Add express.raw to parse bodies into Buffer
express.raw to parse bodies into Buffer
express.text to parse bodies into stringres.sendFilenull/undefined to res.statusX-Forwarded-Hostpb) supportSameSite=None supportContent-Security-Policy headerpath.normalize call103 Early Hintsthrow on invalid typeFix deprecation warnings on Node.js 10+
"Request aborted" may be logged in res.sendfile
Router constructorperf: remove argument reassignment
% as last characterFix TypeError in res.send when given Buffer and ETag header set
TypeError in res.send when given Buffer and ETag header set
X-Forwarded-Proto headerFix regression when root is incorrectly set to a file
root is incorrectly set to a fileAdd "json escape" setting for res.json and res.jsonp
"json escape" setting for res.json and res.jsonp
express.json and express.urlencoded to parse bodiesoptions argument to res.downloadBuffer encoding when not generating ETag for small responsesafe-buffer for improved Buffer APIres.headersSent when availableRegExpX-Forwarded-ForX-Forwarded-For headerimmutable option</html> in default error & redirectsimmutable option.charset set in res.jsonpFix handling of modified headers with invalid dates
If-None-Match token parsingIf-Match token parsingRemove unnecessary Buffer loading
Buffer loadingFix error when res.set cannot add charset to Content-Type
res.set cannot add charset to Content-Type
DEBUG_MAX_ARRAY_LENGTH</html> in HTML documentFix regression parsing keys starting with [
[Fix issue when Date.parse does not return NaN on invalid date
Date.parse does not return NaN on invalid dateDate.parse does not return NaN on invalid dateDeprecated DEBUG_FD environment variable set to 3 or higher
next("router") to exit from routerrouter.use skipped requests routes did notres._headers private field
req.url is not set%o in path debug to tell types apartObject.create to setup request & response prototypessetprototypeof module to replace __proto__ settingstatuses instead of http module for status messagesDEBUG_FD environment variable set to 3 or highererr cannot be converted to a stringContent-Security-Policy: default-src 'self' headerno-cache request directiveIf-None-Match has both * and ETagsETag matching to match specIf-None-Match when no ETag headerDate.parse instead of new Dateno-cache request directiveIf-None-Match has both * and ETagsETag matching to match specres._headers private fieldIf-Match and If-Unmodified-Since headersres.getHeaderNames() when availableres.headersSent when availableno-cache request directiveIf-None-Match has both * and ETagsETag matching to match specres._headers private fieldIf-Match and If-Unmodified-Since headersres.getHeaderNames() when availableres.headersSent when available* routereq.ips performancedeps: content-disposition@0.5.2
err.headers is not an objectAdd acceptRanges option to res.sendFile/res.sendfile
acceptRanges option to res.sendFile/res.sendfilecacheControl option to res.sendFile/res.sendfileoptions argument to req.range
combine optionres.location/res.redirect if not already encodedres.sendFile/res.sendfilereq.get()res.json/res.jsonp in most casesRange header handling in res.sendFile/res.sendfileAccept parsingAccept parameters with quoted equalsAccept parameters with quoted semicolonssameSite optionMax-Age to never be a floating point numberencode is not a functionexpires is not a Dateserializeerr.statusCode if err.status is invaliderr.headers objectstatuses instead of http module for status messagesdecoder option in parse functioncombine option to combine overlapping rangesacceptRanges optioncacheControl optionStream classContent-Range header in 416 responses when using start/end optionsContent-Range header missing from default 416 responsespath contains raw non-URL characterspath starts with multiple forward slashesRange headersacceptRanges optioncacheControl optionreq.url contains raw non-URL charactersRange headersfield argumentdeps: content-disposition@0.5.1
serializeFix infinite loop condition using mergeParams: true
mergeParams: truereq.paramsFix regression with escaped round brackets and matching groups
Fix dropping parameters like hasOwnProperty
hasOwnPropertyFix res.format error when only default provided
res.format error when only default providednext('route') in app.param would incorrectly skip valuesdecodeURIComponent
URIErrors are a 400* before params in routesres.cookie to call res.appendarray-flatten module for flattening arraysstatusCode property on Error objectsunpipe module for unpiping requestsETag matching supportCONNECT requestsUpgrade requestsDate response headerContent-Location on 304 responsehttp-errors for standard emitted errorsstatuses instead of http module for status messagesfallthrough optionnext() instead of 400app.render try blockViewhttp.STATUS_CODESSupport "fake" stats objects in environments without fs
fsisFinished(req) when data bufferedconstructorFix high intensity foreground color for bold
hasOwnProperty is presentextensions or index optionsFix regression where "Request aborted" is logged using res.sendFile
"Request aborted" is logged using res.sendFileFix constructing application with non-configurable prototype properties
ECONNRESET errors from res.sendFile usagereq.host when using "trust proxy" hops countreq.protocol/req.secure when using "trust proxy" hops countcode on aborted connections from res.sendFileFix "trust proxy" setting to inherit when app is mounted
"trust proxy" setting to inherit when app is mountedETags for all request responses
GET and HEAD requestscontent-type to parse Content-Type headersoptionshasBody Transfer-Encoding check*/*)Fix res.redirect double-calling res.end for HEAD requests
res.redirect double-calling res.end for HEAD requestsFix redirect loop in Node.js 0.11.14
Your coding agent can read these notes before it upgrades. Set up the MCP server →