CVE-2026-21714

Red Hat Security Advisory: nodejs24 security update

mediumEPSS 0.4%

Description

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.

Metrics

Severity
medium
no public PoC known
5.3
Source: nvd-v3
38.1 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.4 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-04-13 02:27 UTC

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-08-19 13:35 UTC· nvd@nist.gov
    • CPE Configuration: OR *cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* versions from (including) 24.0.0 up to (including) 24.14.0 *cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* versions from (including) 25.0.0 up to (including) 25.8.1 *cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* versions up to (including) 20.20.1 *cpe:2.3:a:nodejs:node.js:*:*:*:*:-:*:*:* versions from (including) 22.0.0 up to (including) 22.22.1
    • Reference Type: HackerOne: https://nodejs.org/en/blog/vulnerability/march-2026-security-releases Types: Vendor Advisory

Affected operating systems

  • linux

    redhat / enterprise_linux10.0

  • linux

    redhat / enterprise_linux8.0

  • linux

    redhat / enterprise_linux9.0

  • linux

    redhat / enterprise_linux_eus10.0

  • linux

    redhat / enterprise_linux_eus9.4

  • linux

    redhat / enterprise_linux_eus9.6

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    node-min21.0.0

  • bitnami

    node-min23.0.0

  • bitnami

    node-min24.0.0

  • bitnami

    node-min25.0.0

  • IBM

    Concert< 3.0.0

    fixed in 3.0.0

  • nghttp2

    nghttp21.68.1

  • nodejs

    undici7.0.0 – 7.24.0

  • nodejs

    undici6.24.0

  • npm

    undici7.0.0

  • npm

    undici7.17.0

  • npm

    undici

References & sources

Linked CVEs

IDCVE-2026-21714