PT-2026-66439 · Openjs Foundation+1 · Node.Js+1

CVE-2026-56846

·

Published

2026-07-30

·

Updated

2026-09-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Node.js versions 22.x Node.js versions 24.x
Description A flaw in the HTTP/2 handling allows retained header blocks to evade maxSessionMemory, which can lead to remote memory exhaustion. Memory exhaustion occurs when a system consumes all available RAM, potentially causing the application to crash or become unresponsive.
Recommendations Update Node.js version 22.x to the latest patched release. Update Node.js version 24.x to the latest patched release.

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:61376
ALSA-2026:61377
ALSA-2026:61383
ALSA-2026:61386
ALSA-2026:62583
BIT-NODE-2026-56846
BIT-NODE-MIN-2026-56846
CVE-2026-56846
ECHO-49F1-BE71-D1B8
OPENSUSE-SU-2026:11439-1
OPENSUSE-SU-2026:11440-1
OPENSUSE-SU-2026:21545-1
OPENSUSE-SU-2026:21546-1
RHSA-2026:48305
RHSA-2026:61376
RHSA-2026:61377
RHSA-2026:61383
RHSA-2026:61386
RHSA-2026:62219
SUSE-SU-2026:23130-1
SUSE-SU-2026:23131-1
SUSE-SU-2026:23154-1
SUSE-SU-2026:23155-1
SUSE-SU-2026:3520-1
SUSE-SU-2026:3521-1
SUSE-SU-2026:3557-1
SUSE-SU-2026:3929-1
SUSE-SU-2026:3930-1

Affected Products

Node.Js
Rocky Linux