
Cloud Vulnerability DB
Eine von der Community geführte Datenbank für Schwachstellen
CVE-2026-56846 is a high-severity vulnerability in Node.js's HTTP/2 implementation where retained header blocks can bypass maxSessionMemory limits, leading to remote memory exhaustion. It was disclosed on July 29, 2026, as part of Node.js's July 2026 security release batch. The vulnerability affects all users on active release lines 22.x and 24.x. The CVE is estimated as Medium–High severity by Feedly, and the Node.js project classifies it as High (Node.js Advisory).
The root cause is a flaw in Node.js's HTTP/2 session accounting logic, where retained header blocks are not properly tracked against the maxSessionMemory configuration limit. This allows an attacker to send crafted HTTP/2 requests with large or numerous header blocks that accumulate in memory without being counted toward the session memory cap, effectively bypassing the intended resource constraint. The vulnerability is remotely exploitable without authentication, requiring only network access to an HTTP/2-enabled Node.js server. The reporter is credited as leduckhuong, and the fix was authored by mcollina (Node.js Advisory).
Successful exploitation results in remote memory exhaustion on the affected Node.js server, constituting a Denial of Service (DoS) condition. An unauthenticated remote attacker can repeatedly send HTTP/2 requests with retained header blocks to consume server memory beyond configured limits, potentially crashing the process or degrading service availability for all users. Confidentiality and integrity are not directly impacted, but availability is severely affected (Node.js Advisory).
maxSessionMemory.dmesg, journalctl) recording OOM killer events targeting the Node.js process.The Node.js project released patched versions on July 29, 2026: v22.23.2 (for the 22.x line) and v24.18.1 (for the 24.x line). Users should upgrade to these versions immediately. As a temporary workaround, operators may consider disabling HTTP/2 support if not required, or placing a reverse proxy (e.g., nginx) in front of Node.js to enforce stricter HTTP/2 header limits. End-of-Life Node.js versions are also affected and should be migrated to a supported release line (Node.js Advisory, Node.js v22.23.2 Release, Node.js v24.18.1 Release).
The July 2026 Node.js security release, which includes CVE-2026-56846, received coverage from multiple security news outlets including CyberSecurityNews, CyberPress, and SecurityOnline, noting that Node.js fixed 11 security flaws capable of crashing servers and breaking filesystem restrictions. The Linux-compatible community highlighted the emergency nature of the patch batch. No notable individual researcher commentary or significant social media controversy has been identified beyond standard patch notification discussions (CyberSecurityNews, SecurityOnline).
Quelle: Dieser Bericht wurde mithilfe von KI erstellt
Kostenlose Schwachstellenbewertung
Bewerten Sie Ihre Cloud-Sicherheitspraktiken in 9 Sicherheitsbereichen, um Ihr Risikoniveau zu bewerten und Lücken in Ihren Abwehrmaßnahmen zu identifizieren.
Eine personalisierte Demo anfordern
"Die beste Benutzererfahrung, die ich je gesehen habe, bietet vollständige Transparenz für Cloud-Workloads."
"„Wiz bietet eine zentrale Oberfläche, um zu sehen, was in unseren Cloud-Umgebungen vor sich geht.“ "
"„Wir wissen, dass, wenn Wiz etwas als kritisch identifiziert, es auch wirklich kritisch ist.“"