Node.js
cpe:2.3:a:nodejs:node.js:*:*:*:*:*:*:*, +2 more
- ~20
- ~22
- ~24
- ~25
A memory leak vulnerability has been identified in Node.js HTTP/2 servers in versions 20.x, 22.x, 24.x, and 25.x. The issue arises when a client sends WINDOW_UPDATE frames on stream 0, causing the flow control window to exceed the maximum limit. While the server responds appropriately by sending a GOAWAY frame, the Http2Session object is not properly cleaned up, leading to resource exhaustion.
Exploitation of this vulnerability causes a memory leak that can lead to resource exhaustion on the server.
Users can upgrade to Node.js versions 20.20.2, 22.22.2, 24.14.1, or 25.8.2 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.