{"id":"CVE-2026-56846","aliases":["BIT-node-min-2026-56846"],"url":"https://o3.security/vulnerability/CVE-2026-56846","summary":null,"details":"A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion.\r\n\r\nThis vulnerability affects Node.js **24.x** and **22.x**.","published":"2026-08-17T05:52:22.094Z","modified":"2026-08-17T08:11:07.646384020Z","cvss":null,"epss":{"score":0.005,"percentile":0.4166,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Bitnami","name":"node","fixedVersion":"22.23.2"}],"fix":null,"references":[{"type":"WEB","url":"https://nodejs.org/en/blog/vulnerability/july-2026-security-releases"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56846"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-17T08:11:07.646384020Z"}}