Описание
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion.
This vulnerability affects Node.js 24.x and 22.x.
A flaw was found in Node.js's handling of HTTP/2. This vulnerability allows a remote attacker to bypass maxSessionMemory limits by sending specially crafted HTTP/2 retained header blocks. This can lead to memory exhaustion, resulting in a denial of service (DoS) for the affected system.
Отчет
This Important flaw in Node.js HTTP/2 handling allows a remote attacker to bypass maxSessionMemory limits by sending specially crafted header blocks. This can lead to memory exhaustion and a denial of service for Node.js applications configured to use HTTP/2, without requiring authentication or user interaction.
Меры по смягчению последствий
To mitigate this issue, restrict network access to Node.js applications utilizing HTTP/2 to trusted clients only, by implementing firewall rules or network access controls. If HTTP/2 functionality is not essential for the application, consider disabling it in the Node.js configuration to prevent exploitation. Always ensure that any service restarts or reloads are performed carefully to avoid service disruption.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 9 | nodejs:26/nodejs | Affected | ||
| Red Hat Hardened Images | nodejs20 | Not affected | ||
| Red Hat Hardened Images | nodejs25 | Not affected | ||
| Red Hat Hardened Images | nodejs26 | Not affected | ||
| Red Hat Enterprise Linux 10 | nodejs22 | Fixed | RHSA-2026:61376 | 31.08.2026 |
| Red Hat Enterprise Linux 10 | nodejs24 | Fixed | RHSA-2026:61377 | 31.08.2026 |
| Red Hat Enterprise Linux 8 | nodejs | Fixed | RHSA-2026:62219 | 01.09.2026 |
| Red Hat Enterprise Linux 8 | nodejs | Fixed | RHSA-2026:62583 | 02.09.2026 |
| Red Hat Enterprise Linux 9 | nodejs | Fixed | RHSA-2026:61383 | 31.08.2026 |
| Red Hat Enterprise Linux 9 | nodejs | Fixed | RHSA-2026:61386 | 31.08.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blo ...
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.
EPSS
7.5 High
CVSS3