CVE-2026-21714
Red Hat Security Advisory: nodejs24 security update
Description
A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.
Metrics
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-08-19 13:35 UTC· nvd@nist.gov
- CPE Configuration: OR *cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* versions from (including) 24.0.0 up to (including) 24.14.0 *cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* versions from (including) 25.0.0 up to (including) 25.8.1 *cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* versions up to (including) 20.20.1 *cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* versions from (including) 22.0.0 up to (including) 22.22.1
- Reference Type: HackerOne: https://nodejs.org/en/blog/vulnerability/march-2026-security-releases Types: Vendor Advisory
Affected operating systems
linux
redhat / enterprise_linux10.0
linux
redhat / enterprise_linux8.0
linux
redhat / enterprise_linux9.0
linux
redhat / enterprise_linux_eus10.0
linux
redhat / enterprise_linux_eus9.4
linux
redhat / enterprise_linux_eus9.6
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
bitnami
node-min21.0.0
bitnami
node-min23.0.0
bitnami
node-min24.0.0
bitnami
node-min25.0.0
IBM
Concert< 3.0.0
fixed in 3.0.0
nghttp2
nghttp21.68.1
nodejs
undici7.0.0 – 7.24.0
nodejs
undici6.24.0
npm
undici7.0.0
npm
undici7.17.0
npm
undici
References & sources
- https://github.com/nodejs/undici/security/advisories/GHSA-4992-7rv2-5pvqweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-1527advisory
- https://hackerone.com/reports/3487198web
- https://cna.openjsf.org/security-advisories.htmlweb
- https://github.com/nodejs/undicipackage
- https://github.com/nodejs/undici/security/advisories/GHSA-phc3-fgpg-7m6hweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-2581advisory
- https://hackerone.com/reports/3513473web
- https://nodejs.org/en/blog/vulnerability/march-2026-security-releases
- https://nvd.nist.gov/vuln/detail/CVE-2026-21716web
- https://github.com/nodejs/undici/security/advisories/GHSA-2mjp-6q6p-2qxmweb
- https://nvd.nist.gov/vuln/detail/CVE-2026-1525advisory
- https://hackerone.com/reports/3556037web
- https://cwe.mitre.org/data/definitions/444.htmlweb
- https://www.rfc-editor.org/rfc/rfc9110.html#section-8.6web
- https://nvd.nist.gov/vuln/detail/CVE-2026-21714web
- https://nvd.nist.gov/vuln/detail/CVE-2026-21717web
- https://github.com/isaacs/minimatch/security/advisories/GHSA-3ppc-4f35-3m26web
- https://nvd.nist.gov/vuln/detail/CVE-2026-26996advisory
- https://github.com/isaacs/minimatch/commit/2e111f3a79abc00fa73110195de2c0f2351904f5web
Linked CVEs
- CVE-2026-27135
A flaw was found in nghttp2.
highCVSSv3 7.5 - CVE-2026-26996
A flaw was found in minimatch.
high - CVE-2026-2581
This is an uncontrolled resource consumption vulnerability (CWE-400) that can lead to Denial of Service (DoS).
mediumCVSSv3 5.9 - CVE-2026-25547
@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion.
critical - CVE-2026-2229
A flaw was found in the undici WebSocket client.
highCVSSv3 7.5 - CVE-2026-21717
A flaw was found in V8's string hashing mechanism within Node.js.
mediumCVSSv3 5.9 - CVE-2026-21716
A flaw was found in Node.js.
lowCVSSv3 3.3 - CVE-2026-21715
A flaw in Node.js Permission Model filesystem enforcement leaves `fs.realpathSync.native()` without the required read permission checks,…
lowCVSSv3 3.3 - CVE-2026-21713
A flaw in Node.js HMAC verification uses a non-constant-time comparison when validating user-provided signatures, potentially leaking tim…
mediumCVSSv3 5.9 - CVE-2026-21712
A flaw in Node.js URL processing causes an assertion failure in native code when `url.format()` is called with a malformed internationali…
mediumCVSSv3 6.5 - CVE-2026-21711
A flaw in Node.js Permission Model network enforcement leaves Unix Domain Socket (UDS) server operations without the required permission…
mediumCVSSv3 5.3 - CVE-2026-21710
A flaw in Node.js HTTP request handling causes an uncaught `TypeError` when a request is received with a header named `__proto__` and the…
highCVSSv3 7.5 - CVE-2026-21637
A flaw in Node.js TLS error handling allows remote attackers to crash or exhaust resources of a TLS server when `pskCallback` or `ALPNCal…
highCVSSv3 7.5 - CVE-2026-1528
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-1527
A flaw was found in undici, a Node.js HTTP/1.1 client.
mediumCVSSv3 4.6 - CVE-2026-1526
A flaw was found in undici.
highCVSSv3 7.5 - CVE-2026-1525
A flaw was found in undici, a Node.js HTTP/1.1 client.
mediumCVSSv3 6.5