5.3

CVE-2026-21714

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up.

This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nodejs ≫ Node.Js SwEdition - Version <= 20.20.1
Nodejs ≫ Node.Js SwEdition - Version >= 22.0.0 <= 22.22.1
Nodejs ≫ Node.Js SwEdition - Version >= 24.0.0 <= 24.14.0
Nodejs ≫ Node.Js SwEdition - Version >= 25.0.0 <= 25.8.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.359
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
HackerOne 5.3 3.9 1.4
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-401 Missing Release of Memory after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

https://nodejs.org/en/blog/vulnerability/march-2026-security-releases
Vendor Advisory