CVE-2026-56846 PUBLISHED

Assigner: hackerone
Reserved: 23.06.2026 Published: 04.08.2026 Updated: 04.08.2026

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion.

This vulnerability affects Node.js 24.x and 22.x.

Metrics

CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor nodejs
Product node
Versions Default: unaffected
  • affected from 24.18.0 to 24.18.0 (incl.)
  • affected from 22.23.1 to 22.23.1 (incl.)

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE