Junglewise Threat Intelligence

CVE-2026-48937: Node.js HTTP/2 resource exhaustion after GOAWAY frame

CVE-2026-48937 · Severity: medium · CVSS 5.3 · Published 2026-06-18

Executive brief

A vulnerability in the Node.js HTTP/2 server implementation can cause servers to continue processing incoming data even after they have signaled for a connection to close. This failure to properly terminate sessions can lead to excessive resource consumption, potentially impacting the availability and performance of web applications. Organizations using affected versions of Node.js should update to the latest security releases to ensure connections are closed correctly.

Technical details

A vulnerability exists in the Node.js HTTP/2 server API where sessions are not correctly terminated following the transmission of a GOAWAY frame triggered by invalid protocol errors. This root cause allows a remote attacker to continue sending data to the server despite the connection being marked for closure, leading to uncontrolled resource consumption (CWE-400). The issue specifically affects the HTTP/2 server implementation in Node.js versions 22 and 24. Security updates (v22.23.0 and v24.17.0) have been released to ensure sessions are properly cleaned up and resources are released.

Affected products

  • Node.js Node.js 22.x, 24.x

Timeline

  • 2026-06-18: disclosed
  • 2026-06-18: advisory
  • 2026-06-18: patched

References