Node.js
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*, +2 more
- ~20
- ~22
- ~24
- ~25
A denial-of-service vulnerability has been identified in Node.js HTTP/2 server handling. When a malformed HEADERS frame containing oversized, invalid HPACK data is received, it triggers an unhandled error in the TLSSocket, causing the Node.js process to crash. This issue primarily affects applications that do not implement explicit error handlers for secure sockets, leading to a remote denial-of-service condition.
Exploitation of this vulnerability causes the Node.js process to crash, disrupting the application and potentially leading to resource exhaustion.
Users can update to Node.js versions 25.3.0, 24.13.0, or 22.22.0, all of which include the necessary fix. Instructions for downloading these versions are available on the Node.js website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.