- Description
- A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerability affects Node.js **26.x**, **24.x**, and **22.x**.
- Source
- support@hackerone.com
- NVD status
- Awaiting Analysis
CVSS 3.0
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- support@hackerone.com
- CWE-416
- Hype score
- Not currently trending
CVE-2026-56848: Node.js HTTP/2 Heap Use-After-Free - What It Means for Your Business and How to Respond https://t.co/4fIVrZpV8x
@integ_sec
2 Sept 2026
28 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
Node.js 2026年7月のパッチで11件の脆弱性を修正(CVE-2026-56846,CVE-2026-56848)等 https://t.co/7A0Bg4pFQT #セキュリティ対策Lab #security #securitynews #脆弱性
@securityLab_jp
3 Aug 2026
209 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-56846, CVE-2026-56848 & CVE-2026-58043 and other: 3 high-severity and 8 medium or low vulnerabilities in Node.js 🔥 Recently disclosed vulnerabilities in Node.js touch HTTP/2, the Permission Model, and several core modules. 👉 https://t.co/JHr4MEmONt https:/
@Netlas_io
30 Jul 2026
538 Impressions
3 Retweets
8 Likes
1 Bookmark
0 Replies
0 Quotes
Node.jsで11件の脆弱性が修正。うち、深刻度「高」が3件。HTTP/2におけるヒープ解放後メモリ使用CVE-2026-56848、HTTP/2のメモリ枯渇CVE-2026-56846、過剰なファイルシステムアクセス許可CVE-2026-58043。 https://t.co/W5zRutPGEV
@__kokumoto
30 Jul 2026
750 Impressions
1 Retweet
6 Likes
2 Bookmarks
0 Replies
0 Quotes