CVE-2026-56846

Summary

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion.

This vulnerability affects Node.js 24.x and 22.x.

Affected Software

VendorProductVersion RangeStatus
nodejsnode24.18.0 <= 24.18.0affected
nodejsnode22.23.1 <= 22.23.1affected

Weaknesses

  • CWE-400: CWE-400 Uncontrolled Resource Consumption

References