PT-2026-66440 · Openjs Foundation+1 · Node.Js+1

CVE-2026-56848

·

Published

2026-07-30

·

Updated

2026-09-03

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Node.js versions 22.x Node.js versions 24.x Node.js versions 26.x
Description A flaw in HTTP/2 handling allows the nghttp2 session mem send() function to be called re-entrantly while nghttp2 session mem recv() is executing. This sequence leads to a heap-use-after-free, which occurs when the program continues to use a pointer after the memory it points to has been freed.
Recommendations Update Node.js version 22.x to the latest patched release. Update Node.js version 24.x to the latest patched release. Update Node.js version 26.x to the latest patched release.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:61376
ALSA-2026:61377
ALSA-2026:61383
ALSA-2026:61386
ALSA-2026:62583
BIT-NODE-2026-56848
BIT-NODE-MIN-2026-56848
CVE-2026-56848
ECHO-5503-28CB-5D02
OPENSUSE-SU-2026:11439-1
OPENSUSE-SU-2026:11440-1
OPENSUSE-SU-2026:21545-1
OPENSUSE-SU-2026:21546-1
SUSE-SU-2026:23130-1
SUSE-SU-2026:23131-1
SUSE-SU-2026:23154-1
SUSE-SU-2026:23155-1
SUSE-SU-2026:3520-1
SUSE-SU-2026:3521-1
SUSE-SU-2026:3557-1
SUSE-SU-2026:3929-1
SUSE-SU-2026:3930-1

Affected Products

Node.Js
Rocky Linux