CVE-2026-56846: High severity Node.js Node.js vulnerability
Published Aug 4, 2026
·Updated
A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnerability affects Node.js 24.x and 22.x.
Affected Software
1 affected component
Node.js Node.js>=22<=22, >=24<=24
Event History
Aug 4, 2026
CVE Published
via MITRE·12:49 AM
Data Sourced
via MITRE·12:49 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-56846?
The severity of CVE-2026-56846 is rated as high with a score of 7.5.
2
How do I fix CVE-2026-56846?
To fix CVE-2026-56846, upgrade to a patched version of Node.js that addresses the HTTP/2 handling flaw.
3
What versions of Node.js are affected by CVE-2026-56846?
CVE-2026-56846 affects Node.js versions 24.x and 22.x.
4
What impact does CVE-2026-56846 have on an application?
CVE-2026-56846 can cause remote memory exhaustion due to HTTP/2 retained header blocks evading maxSessionMemory.
5
Is there a workaround for CVE-2026-56846?
Currently, there are no known workarounds for CVE-2026-56846, and users are advised to update Node.js.