CVE-2026-48937: High severity OpenJS Foundation Node.js vulnerability
Published Jun 18, 2026
·Updated
A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a GOAWAY frame. This vulnerability affects two supported release lines: Node.js 22 and Node.js 24.
Affected Software
3 affected components
OpenJS Foundation Node.js=22, =24
Nodejs Node.js>=22.0<22.23.0
Nodejs Node.js>=24.0.0<24.17.0
Event History
Jun 18, 2026
CVE Published
via MITRE·06:01 PM
Data Sourced
via MITRE·06:01 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48937?
The severity of CVE-2026-48937 is rated as medium with a score of 5.3.
2
Which versions of Node.js are affected by CVE-2026-48937?
CVE-2026-48937 affects Node.js version 22 and version 24.
3
What is the impact of CVE-2026-48937?
CVE-2026-48937 allows servers to continue accepting data after a `GOAWAY` frame has been sent.
4
How do I fix CVE-2026-48937?
To mitigate CVE-2026-48937, upgrade to a patched version of Node.js provided by OpenJS Foundation.
5
Does CVE-2026-48937 affect the confidentiality of data?
CVE-2026-48937 does not impact the confidentiality of data as it primarily affects data flow during connections.