Openjs Foundation · Node.Js · CVE-2026-48619
**Name of the Vulnerable Software and Affected Versions**
Node.js versions 22.x, 24.x, and 26.x prior to 26.3.1-1.1
**Description**
A flaw in the Node.js HTTP/2 client enables a server to send an unlimited number of ORIGIN frames, potentially causing an Out of Memory error on the client side.
**Recommendations**
Update Node.js to version 26.3.1-1.1 or later.