GHSA-679w-638g-xf9hHighCVSS 7.5

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly...

Published
August 4, 2026
Last Modified
August 4, 2026

🔗 CVE IDs covered (1)

📋 Description

A flaw in Node.js HTTP/2 handling allows nghttp2_session_mem_send() to be called re-entrantly while nghttp2_session_mem_recv() is executing, resulting in a heap-use-after-free.

This vulnerability affects Node.js 26.x, 24.x, and 22.x.

🔗 References (3)