ΠΠΎΠ»ΠΈΡΠ΅ΡΡΠ²ΠΎ 26
ΠΠΎΠ»ΠΈΡΠ΅ΡΡΠ²ΠΎ 26
GHSA-679w-638g-xf9h
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
CVE-2026-56848
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
CVE-2026-56848
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
CVE-2026-56848
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
CVE-2026-56848
A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` ...
RLSA-2026:62583
Important: nodejs:24 security update
RLSA-2026:62219
Important: nodejs:22 security update
RLSA-2026:61386
Important: nodejs:24 security update
RLSA-2026:61383
Important: nodejs:22 security update
RLSA-2026:61377
Important: nodejs24 security, bug fix, and enhancement update
RLSA-2026:61376
Important: nodejs22 security update
ELSA-2026-62583-0
ELSA-2026-62583-0: nodejs:24 security update (IMPORTANT)
ELSA-2026-62219-0
ELSA-2026-62219-0: nodejs:22 security update (IMPORTANT)
ELSA-2026-61386-0
ELSA-2026-61386-0: nodejs:24 security update (IMPORTANT)
ELSA-2026-61383-0
ELSA-2026-61383-0: nodejs:22 security update (IMPORTANT)
ELSA-2026-61377-0
ELSA-2026-61377-0: nodejs24 security, bug fix, and enhancement update (IMPORTANT)
ELSA-2026-61376-0
ELSA-2026-61376-0: nodejs22 security update (IMPORTANT)
openSUSE-SU-2026:21545-1
Security update for nodejs22
SUSE-SU-2026:3557-1
Security update for nodejs22
SUSE-SU-2026:3521-1
Security update for nodejs22
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΠ΅ΠΉ Π½Π° ΡΡΡΠ°Π½ΠΈΡΡ
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΡ | CVSS | EPSS | ΠΠΏΡΠ±Π»ΠΈΠΊΠΎΠ²Π°Π½ΠΎ | |
|---|---|---|---|---|
GHSA-679w-638g-xf9h A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**. | CVSS3: 7.5 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | ΠΎΠΊΠΎΠ»ΠΎ 2 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | |
CVE-2026-56848 A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**. | CVSS3: 7.5 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | ΠΎΠΊΠΎΠ»ΠΎ 2 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | |
CVE-2026-56848 A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**. | CVSS3: 7.5 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | ΠΎΠΊΠΎΠ»ΠΎ 2 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | |
CVE-2026-56848 A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**. | CVSS3: 7.5 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | ΠΎΠΊΠΎΠ»ΠΎ 2 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | |
CVE-2026-56848 A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` ... | CVSS3: 7.5 | 0% ΠΠΈΠ·ΠΊΠΈΠΉ | ΠΎΠΊΠΎΠ»ΠΎ 2 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ | |
RLSA-2026:62583 Important: nodejs:24 security update | 19 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄ | |||
RLSA-2026:62219 Important: nodejs:22 security update | 20 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄ | |||
RLSA-2026:61386 Important: nodejs:24 security update | 21 Π΄Π΅Π½Ρ Π½Π°Π·Π°Π΄ | |||
RLSA-2026:61383 Important: nodejs:22 security update | 21 Π΄Π΅Π½Ρ Π½Π°Π·Π°Π΄ | |||
RLSA-2026:61377 Important: nodejs24 security, bug fix, and enhancement update | 19 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄ | |||
RLSA-2026:61376 Important: nodejs22 security update | 19 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄ | |||
ELSA-2026-62583-0 ELSA-2026-62583-0: nodejs:24 security update (IMPORTANT) | 19 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄ | |||
ELSA-2026-62219-0 ELSA-2026-62219-0: nodejs:22 security update (IMPORTANT) | 20 Π΄Π½Π΅ΠΉ Π½Π°Π·Π°Π΄ | |||
ELSA-2026-61386-0 ELSA-2026-61386-0: nodejs:24 security update (IMPORTANT) | 21 Π΄Π΅Π½Ρ Π½Π°Π·Π°Π΄ | |||
ELSA-2026-61383-0 ELSA-2026-61383-0: nodejs:22 security update (IMPORTANT) | 21 Π΄Π΅Π½Ρ Π½Π°Π·Π°Π΄ | |||
ELSA-2026-61377-0 ELSA-2026-61377-0: nodejs24 security, bug fix, and enhancement update (IMPORTANT) | 21 Π΄Π΅Π½Ρ Π½Π°Π·Π°Π΄ | |||
ELSA-2026-61376-0 ELSA-2026-61376-0: nodejs22 security update (IMPORTANT) | 21 Π΄Π΅Π½Ρ Π½Π°Π·Π°Π΄ | |||
openSUSE-SU-2026:21545-1 Security update for nodejs22 | ΠΎΠΊΠΎΠ»ΠΎ 1 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | |||
SUSE-SU-2026:3557-1 Security update for nodejs22 | ΠΎΠΊΠΎΠ»ΠΎ 1 ΠΌΠ΅ΡΡΡΠ° Π½Π°Π·Π°Π΄ | |||
SUSE-SU-2026:3521-1 Security update for nodejs22 | ΠΎΠΊΠΎΠ»ΠΎ 2 ΠΌΠ΅ΡΡΡΠ΅Π² Π½Π°Π·Π°Π΄ |
Π£ΡΠ·Π²ΠΈΠΌΠΎΡΡΠ΅ΠΉ Π½Π° ΡΡΡΠ°Π½ΠΈΡΡ