What is CVE-2026-56848?
This CVE-2026-56848 describes a flaw in Node.js HTTP/2 handling where the `nghttp2_session_mem_send()` function is called re-entrantly during `nghttp2_session_mem_recv()` execution, leading to a heap-use-after-free vulnerability. It affects Node.js versions 26.x, 24.x, and 22.x. Users are advised to upgrade to the latest patched versions immediately.
Azərbaycanca: Bu CVE-2026-56848, Node.js-in HTTP/2 protokol işlənməsində `nghttp2_session_mem_recv()` icra olunarkən `nghttp2_session_mem_send()` funksiyasının təkrar çağırılması ilə heap-use-after-free boşluğuna səbəb olan qüsuru təsvir edir. Bu zəiflik Node.js-in 26.x, 24.x və 22.x versiyalarına təsir göstərir. İstifadəçilərə təsirlənmiş versiyaları ən son təhlükəsizlik yeniləmələrinə dərhal yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-416
FAQ2
In which protocol handling does CVE-2026-56848 cause a heap-use-after-free vulnerability in Node.js?
In HTTP/2 handling.
What action is recommended for affected Node.js versions to mitigate CVE-2026-56848?
Users are advised to upgrade the affected versions to the latest patched versions immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.