What oven-sh/bun shipped
Written by FoxPlug from public releases; not affiliated with Bun. An automatic summary of the public release, pull request and commit data of github.com/oven-sh/bun. Bun did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- node:http server now follows Node.js behaviour for request body, framing, response finish, and lifecycle. Pull request #43557
- WebKit upgraded to 7b485a76e9, including 970 upstream commits with updates to JavaScriptCore, WTF, and bmalloc. Pull request #43882
- node:http2 now rate-limits stream resets per connection to prevent rapid reset attacks (CVE-2023-44487, CVE-2025-8671). Pull request #36230
- TLS server name validation now rejects non-hostname values that were previously accepted as certificate names. Pull request #43873
- Bundler splitting fixed to prevent shared chunks from importing entry files and running code twice. Pull request #44023
- Bun.serve now refuses Response bodies that a consumer already reads to prevent stack overflow crashes. Pull request #44014
- Code coverage now counts every load of a file, not only the last one. Pull request #43158
- Windows installations no longer hang when replacing a package whose exe holds the last hard link. Pull request #43864
- S3 tests migrated from MinIO container to an S3 server running on Bun.serve. Pull request #44054
- process.exit() now throws proper error messages matching Node.js when process.reallyExit is not callable. Pull request #44057
Why it matters
This week ships fixes for node:http and node:http2 server behaviour, critical TLS and security improvements including rate-limiting for rapid reset attacks, and a major WebKit upgrade. Code coverage, bundler splitting, and Windows stability issues are also resolved, making Bun more compatible with Node.js and more secure.
Changelog entry
- node:http server request body, framing, response finish, and lifecycle now match Node.js behavior Pull request #43557
- WebKit upgraded to 7b485a76e9 with 970 upstream commits Pull request #43882
- node:http2 now rate-limits stream resets per connection to prevent CVE-2023-44487 and CVE-2025-8671 attacks Pull request #36230
- TLS server name validation now strictly checks hostnames and rejects non-hostname values Pull request #43873
- Bundler splitting fixed: shared chunks no longer import entry files, preventing duplicate code execution Pull request #44023
- Bun.serve now rejects Response bodies already consumed by a reader to prevent stack overflow Pull request #44014
- Code coverage now counts every file load, not just the last one Pull request #43158
- Windows bun install no longer hangs when replacing packages with running executables Pull request #43864
- S3 tests migrated from MinIO container to Bun.serve-based S3 server Pull request #44054
- process.exit() throws proper error messages matching Node.js when process.reallyExit is not callable Pull request #44057
- IP address parsing now strictly validates format, rejecting partial notation and CIDR notation as hostnames Pull request #43979
- Build now requires clang's LLVM and rustc's LLVM to be the same major version Pull request #44091
Bun ships node:http server fixes, node:http2 rate-limiting for rapid reset attacks, TLS validation improvements, WebKit upgrade, bundler splitting fixes, and better code coverage counting.
This week's Bun release brings significant improvements across multiple areas. The node:http server now follows Node.js behavior more closely for request handling and lifecycle management. Critical security fixes include rate-limiting for node:http2 stream resets (CVE-2023-44487, CVE-2025-8671). TLS server name validation is stricter, rejecting non-hostname values. WebKit upgraded to include 970 upstream commits. Bundler splitting, code coverage, and Windows package installation stability are improved. These changes enhance Node.js compatibility and security.