CVE-2026-21714

EUVD-2026-17176
A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up.

This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 4%
Debian logo
Debian Releases
Debian Product
Codename
nodejs
bookworm
vulnerable
bookworm (security)
18.20.4+dfsg-1~deb12u2
fixed
bullseye
vulnerable
bullseye (security)
vulnerable
forky
24.15.0+dfsg+~cs24.12.2-1
fixed
sid
24.15.0+dfsg+~cs24.12.2-1
fixed
trixie
vulnerable
trixie (security)
20.19.2+dfsg-1+deb13u2
fixed
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
nodejs20
suse enterprise server 15 SP5
20.20.2-150500.11.27.1
fixed
suse enterprise server 15 SP6
20.20.2-150600.3.18.1
fixed
nodejs20-devel
suse enterprise server 15 SP5
20.20.2-150500.11.27.1
fixed
suse enterprise server 15 SP6
20.20.2-150600.3.18.1
fixed
nodejs20-docs
suse enterprise server 15 SP5
20.20.2-150500.11.27.1
fixed
suse enterprise server 15 SP6
20.20.2-150600.3.18.1
fixed
nodejs22
suse enterprise sap 15 SP7
22.22.2-150700.3.9.1
fixed
suse enterprise server 15 SP6
22.22.2-150600.13.15.1
fixed
suse enterprise server 15 SP7
22.22.2-150700.3.9.1
fixed
nodejs22-devel
suse enterprise sap 15 SP7
22.22.2-150700.3.9.1
fixed
suse enterprise server 15 SP6
22.22.2-150600.13.15.1
fixed
suse enterprise server 15 SP7
22.22.2-150700.3.9.1
fixed
nodejs22-docs
suse enterprise sap 15 SP7
22.22.2-150700.3.9.1
fixed
suse enterprise server 15 SP6
22.22.2-150600.13.15.1
fixed
suse enterprise server 15 SP7
22.22.2-150700.3.9.1
fixed
nodejs24
suse enterprise sap 15 SP7
24.14.1-150700.15.8.1
fixed
suse enterprise server 15 SP7
24.14.1-150700.15.8.1
fixed
nodejs24-devel
suse enterprise sap 15 SP7
24.14.1-150700.15.8.1
fixed
suse enterprise server 15 SP7
24.14.1-150700.15.8.1
fixed
nodejs24-docs
suse enterprise sap 15 SP7
24.14.1-150700.15.8.1
fixed
suse enterprise server 15 SP7
24.14.1-150700.15.8.1
fixed
npm20
suse enterprise server 15 SP5
20.20.2-150500.11.27.1
fixed
suse enterprise server 15 SP6
20.20.2-150600.3.18.1
fixed
npm22
suse enterprise sap 15 SP7
22.22.2-150700.3.9.1
fixed
suse enterprise server 15 SP6
22.22.2-150600.13.15.1
fixed
suse enterprise server 15 SP7
22.22.2-150700.3.9.1
fixed
npm24
suse enterprise sap 15 SP7
24.14.1-150700.15.8.1
fixed
suse enterprise server 15 SP7
24.14.1-150700.15.8.1
fixed