Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56848

Опубликовано: 04 авг. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw in Node.js HTTP/2 handling allows nghttp2_session_mem_send() to be called re-entrantly while nghttp2_session_mem_recv() is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js 26.x, 24.x, and 22.x.

A heap use-after-free vulnerability in the Node.js HTTP/2 component allows a remote attacker to crash the application, causing a denial of service. This is triggered by an unexpected re-entrant call to nghttp2_session_mem_send() while nghttp2_session_mem_recv() is still executing.

Отчет

A remote attacker can exploit an Important heap use-after-free vulnerability in Node.js HTTP/2 to crash applications. The flaw, caused by re-entrant memory operations, leads to a denial of service for Red Hat environments with HTTP/2 enabled.

Меры по смягчению последствий

Restrict network access to Node.js HTTP/2 listeners to trusted clients only. If HTTP/2 is not required, disable it to remove the vulnerable handler from the attack surface.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10nodejs22Affected
Red Hat Enterprise Linux 10nodejs24Affected
Red Hat Enterprise Linux 8nodejs:22/nodejsAffected
Red Hat Enterprise Linux 8nodejs:24/nodejsAffected
Red Hat Enterprise Linux 9nodejs:22/nodejsAffected
Red Hat Enterprise Linux 9nodejs:24/nodejsAffected
Red Hat Enterprise Linux 9nodejs:26/nodejsAffected
Red Hat Hardened Imagesnodejs20Not affected
Red Hat Hardened Imagesnodejs22Not affected
Red Hat Hardened Imagesnodejs24Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2511089nodejs: Node.js: Heap-use-after-free in HTTP/2 handling can lead to denial of service

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CVSS3: 7.5
nvd
около 1 месяца назад

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

CVSS3: 7.5
debian
около 1 месяца назад

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` ...

CVSS3: 7.5
github
около 1 месяца назад

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.

suse-cvrf
около 1 месяца назад

Security update for nodejs22

7.5 High

CVSS3