Resource exhaustion in Node.js - CVE-2026-48619
Published: June 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in node:http2 clients when processing attacker-controlled ORIGIN frames. A remote attacker can send an unlimited number of ORIGIN frames to cause a denial of service.
The issue can lead to an out-of-memory condition on the client.
Affected software
Anolis OS
nodejs-npm
v8-12.4-devel
nodejs
nodejs-devel
nodejs-full-i18n
nodejs-libs
nodejs-docs
How to mitigate CVE-2026-48619
nodejs-npm - update to 10.9.8-1.22.23.0.1
v8-12.4-devel - update to 12.4.254.21-1.22.23.0.1
nodejs - update to 22.23.0-1
nodejs-devel - update to 22.23.0-1
nodejs-full-i18n - update to 22.23.0-1
nodejs-libs - update to 22.23.0-1
nodejs-docs - update to 22.23.0-1