CVE-2026-56846
7.5
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Summary
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion.
This vulnerability affects Node.js 24.x and 22.x.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| nodejs | node | 24.18.0 <= 24.18.0 | affected |
| nodejs | node | 22.23.1 <= 22.23.1 | affected |
Weaknesses
- CWE-400: CWE-400 Uncontrolled Resource Consumption
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.