Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56846

Опубликовано: 04 авг. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js 24.x and 22.x.

A flaw was found in Node.js's handling of HTTP/2. This vulnerability allows a remote attacker to bypass maxSessionMemory limits by sending specially crafted HTTP/2 retained header blocks. This can lead to memory exhaustion, resulting in a denial of service (DoS) for the affected system.

Отчет

This Important flaw in Node.js HTTP/2 handling allows a remote attacker to bypass maxSessionMemory limits by sending specially crafted header blocks. This can lead to memory exhaustion and a denial of service for Node.js applications configured to use HTTP/2, without requiring authentication or user interaction.

Меры по смягчению последствий

To mitigate this issue, restrict network access to Node.js applications utilizing HTTP/2 to trusted clients only, by implementing firewall rules or network access controls. If HTTP/2 functionality is not essential for the application, consider disabling it in the Node.js configuration to prevent exploitation. Always ensure that any service restarts or reloads are performed carefully to avoid service disruption.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 9nodejs:26/nodejsAffected
Red Hat Hardened Imagesnodejs20Not affected
Red Hat Hardened Imagesnodejs25Not affected
Red Hat Hardened Imagesnodejs26Not affected
Red Hat Enterprise Linux 10nodejs22FixedRHSA-2026:6137631.08.2026
Red Hat Enterprise Linux 10nodejs24FixedRHSA-2026:6137731.08.2026
Red Hat Enterprise Linux 8nodejsFixedRHSA-2026:6221901.09.2026
Red Hat Enterprise Linux 8nodejsFixedRHSA-2026:6258302.09.2026
Red Hat Enterprise Linux 9nodejsFixedRHSA-2026:6138331.08.2026
Red Hat Enterprise Linux 9nodejsFixedRHSA-2026:6138631.08.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2510856nodejs: Node.js: Remote memory exhaustion via HTTP/2 retained header blocks

EPSS

Процентиль: 41%
0.005
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.

CVSS3: 7.5
nvd
около 1 месяца назад

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.

CVSS3: 7.5
debian
около 1 месяца назад

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blo ...

CVSS3: 7.5
github
около 1 месяца назад

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.

rocky
12 дней назад

Important: nodejs:24 security update

EPSS

Процентиль: 41%
0.005
Низкий

7.5 High

CVSS3