Executive brief
Node.js HTTP/2 servers have a memory leak vulnerability where malformed WINDOW_UPDATE frames on connection-level streams cause the server to send a graceful shutdown signal but fail to release the associated session object. An attacker can repeatedly trigger this condition to exhaust server memory and cause denial of service.
Technical details
The vulnerability exists in Node.js HTTP/2 server implementation. When a client sends WINDOW_UPDATE frames targeting stream 0 (connection-level) with values that cause the flow control window to exceed 2³¹-1 (INT32_MAX), the server correctly identifies this protocol violation and transmits a GOAWAY frame per HTTP/2 specification. However, the Http2Session object is never properly deallocated in this error path. An attacker can repeatedly send such malformed frames to leak Http2Session objects and exhaust server memory, causing resource exhaustion and denial of service. The vulnerability is triggered via network-reachable HTTP/2 connections and requires no authentication or user interaction. Patches are available in updated releases of Node.js 20.x, 22.x, 24.x, and 25.x.
Affected products
- Node.js Node.js 20.x, 22.x, 24.x, 25.x
Timeline
- 2026-03-24: disclosed: Security release published
- 2026-03-24: patched: Patches released for Node.js 20.x, 22.x, 24.x, 25.x