SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-56846

HIGH · CVSS 7.5 EPSS 0.50%

Source: NVD + CISA KEV + EPSS · Published 2026-08-04 · Last synced 2026-09-03

CyberRota Analysis

AI-Generated

A flaw in the HTTP/2 handling of Node.js versions 24.x and 22.x allows retained header blocks to bypass the maxSessionMemory limit, potentially leading to remote memory exhaustion. This could enable an attacker to deplete server resources, resulting in service degradation or denial of service. Organizations using these versions of Node.js should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-56846
Severity
HIGH
CVSS
7.5
EPSS
0.50%

Original NVD Description

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js **24.x** and **22.x**.