CVE-2026-48619: High severity Node.js 22 vulnerability
A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client.
This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nodejsto a version that resolves this vulnerability.Fixed in 22 - Upgrade
Upgrade
nodejsto a version that resolves this vulnerability.Fixed in 24 - Upgrade
Upgrade
nodejsto a version that resolves this vulnerability.Fixed in 26
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48619?
The severity of CVE-2026-48619 is categorized as high with a score of 7.5.
How do I fix CVE-2026-48619?
To fix CVE-2026-48619, you need to apply the available patch from Node.js.
Which versions of Node.js are affected by CVE-2026-48619?
CVE-2026-48619 affects all supported release lines including Node.js 22, Node.js 24, and Node.js 26.
What kind of error does CVE-2026-48619 cause?
CVE-2026-48619 can lead to an Out of Memory error on the client due to unlimited ORIGIN frames sent by the server.
Is CVE-2026-48619 present in older Node.js versions?
CVE-2026-48619 is not mentioned to affect older versions; it impacts only the supported versions of Node.js.