Heap Use-After-Free Vulnerability in Node.js Products
CVE-2026-56848

7.5HIGH

Key Information:

Vendor

Nodejs

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-56848?

A security flaw in Node.js related to HTTP/2 handling presents a re-entrancy issue that allows the nghttp2_session_mem_send() function to be executed while nghttp2_session_mem_recv() is still running. This can lead to a heap use-after-free condition, potentially allowing attackers to exploit memory management errors. Node.js versions 26.x, 24.x, and 22.x are affected, emphasizing the need for prompt updates to maintain system integrity.

Affected Version(s)

node 26.5.0

node 24.18.0

node 22.23.1

References

CVSS V3.0

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.