CVE-2026-48937
published 2026-06-18CVE-2026-48937: A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.57%
45.4th percentile
A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nodejs | node | 22.22.3 – 22.22.3 | — |
| nodejs | node | 24.16.0 – 24.16.0 | — |
| nodejs | node.js | >= 22.0 < 22.23.0 | 22.23.0 |
| nodejs | node.js | >= 24.0.0 < 24.17.0 | 24.17.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv3.05.3MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Node.js up to 22.22.3/24.16.0 resource consumption (Nessus ID 321755 / WID-SEC-2026-2004)
vuldb·2026-08-18·CVSS 7.5
CVE-2026-48937 [HIGH] Node.js up to 22.22.3/24.16.0 resource consumption (Nessus ID 321755 / WID-SEC-2026-2004)
A vulnerability was found in Node.js up to 22.22.3/24.16.0 and classified as problematic. This affects an unknown part. The manipulation results in resource consumption.
This vulnerability is cataloged as CVE-2026-48937. The attack may be launched remotely. There is no exploit available.
GHSA
A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame.
ghsa_unreviewed·2026-06-18
CVE-2026-48937 [MEDIUM] CWE-400 A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame.
A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**.
Red Hat
nodejs: Node.js HTTP/2 Server: Denial of Service due to continued data acceptance after GOAWAY frame
vendor_redhat·2026-06-18·CVSS 5.3
CVE-2026-48937 [MEDIUM] CWE-400 nodejs: Node.js HTTP/2 Server: Denial of Service due to continued data acceptance after GOAWAY frame
nodejs: Node.js HTTP/2 Server: Denial of Service due to continued data acceptance after GOAWAY frame
A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**.
A flaw in the Node.js HTTP/2 API allows remote attackers to cause a Denial of Service (DoS) by sending data after a GOAWAY frame, exhausting server resources.
Statement: This Moderate DoS flaw in the Node.js HTTP/2 API allows remote attackers to exhaust server resources and cause service unavailability by continuously sending data after a GOAWAY frame.
Mitigation: Restrict Node.js HTTP/2 servers to trusted clients with host firewall or network segmentation. If HTTP/2 is not required, d
No detection rules found.
No public exploits indexed.
2026-06-18
Published