What is CVE-2026-56846?
CVE-2026-56846 is a flaw in Node.js HTTP/2 handling where retained header blocks can evade the `maxSessionMemory` limit, leading to remote memory exhaustion. This affects Node.js versions 24.x and 22.x, requiring immediate update.
Azərbaycanca: CVE-2026-56846 Node.js-in HTTP/2 idarəetmə mexanizmində qüsurdur. Bu qüsur saxlanılan HTTP/2 başlıq bloklarının `maxSessionMemory` limitini keçməsinə yol açır ki, bu da uzaqdan yaddaş tükənməsinə (memory exhaustion) səbəb ola bilər. Node.js 24.x və 22.x versiyaları təsirlənir və dərhal yeniləmə tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
Which platform is affected by the CVE-2026-56846 vulnerability?
This vulnerability affects the HTTP/2 handling mechanism in Node.js.
What can the CVE-2026-56846 flaw lead to?
It can lead to remote memory exhaustion because retained HTTP/2 header blocks evade the `maxSessionMemory` limit.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.