Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-56846

Опубликовано: 04 авг. 2026
Источник: debian
EPSS Низкий

Описание

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
nodejsfixed24.19.0+dfsg+~cs24.13.3-1package

Примечания

  • https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#http2-retained-headers-can-bypass-maxsessionmemory-limits-cve-2026-56846---high

  • Fixed by: https://github.com/nodejs/node/commit/f14d78b9e0201bfe0291f2b0dc4b5d88c70cc28e (v22.23.2)

EPSS

Процентиль: 42%
0.005
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.

CVSS3: 7.5
redhat
около 2 месяцев назад

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.

CVSS3: 7.5
nvd
около 2 месяцев назад

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.

CVSS3: 7.5
github
около 2 месяцев назад

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.

rocky
19 дней назад

Important: nodejs:24 security update

EPSS

Процентиль: 42%
0.005
Низкий