PT-2026-66439 · Openjs Foundation+1 · Node.Js+1
CVE-2026-56846
·
Published
2026-07-30
·
Updated
2026-09-03
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Node.js versions 22.x
Node.js versions 24.x
Description
A flaw in the HTTP/2 handling allows retained header blocks to evade
maxSessionMemory, which can lead to remote memory exhaustion. Memory exhaustion occurs when a system consumes all available RAM, potentially causing the application to crash or become unresponsive.Recommendations
Update Node.js version 22.x to the latest patched release.
Update Node.js version 24.x to the latest patched release.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Node.Js
Rocky Linux