Логотип exploitDog
bind:CVE-2026-21714
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2026-21714

Количество 6

Количество 6

ubuntu логотип

CVE-2026-21714

7 дней назад

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2026-21714

7 дней назад

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-21714

7 дней назад

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.

CVSS3: 5.3
EPSS: Низкий
msrc логотип

CVE-2026-21714

5 дней назад

EPSS: Низкий
debian логотип

CVE-2026-21714

7 дней назад

A memory leak occurs in Node.js HTTP/2 servers when a client sends WIN ...

CVSS3: 5.3
EPSS: Низкий
github логотип

GHSA-cfr8-f5q7-84wq

6 дней назад

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-21714

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.

CVSS3: 5.3
0%
Низкий
7 дней назад
redhat логотип
CVE-2026-21714

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.

CVSS3: 5.3
0%
Низкий
7 дней назад
nvd логотип
CVE-2026-21714

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.

CVSS3: 5.3
0%
Низкий
7 дней назад
msrc логотип
0%
Низкий
5 дней назад
debian логотип
CVE-2026-21714

A memory leak occurs in Node.js HTTP/2 servers when a client sends WIN ...

CVSS3: 5.3
0%
Низкий
7 дней назад
github логотип
GHSA-cfr8-f5q7-84wq

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.

CVSS3: 5.3
0%
Низкий
6 дней назад

Уязвимостей на страницу