REDHAT-BUG-2493325: Medium severity OpenJS Node.js 22 vulnerability
Published Jun 26, 2026
·Updated
A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client.
This vulnerability affects all supported release lines: Node.js 22, Node.js 24, and Node.js 26.
Affected Software
3 affected components
OpenJS Node.js 22
OpenJS Node.js 24
OpenJS Node.js 26
Event History
Jun 26, 2026
Data Sourced
via Red Hat·02:01 AM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2493325?
The severity of REDHAT-BUG-2493325 is medium with a rating of 4.
2
How do I fix REDHAT-BUG-2493325?
To fix REDHAT-BUG-2493325, update your Node.js installation to the latest supported release.
3
What impact does REDHAT-BUG-2493325 have on Node.js applications?
REDHAT-BUG-2493325 can lead to an Out of Memory error on the client if unlimited ORIGIN frames are sent from a server.
4
Which versions of Node.js are affected by REDHAT-BUG-2493325?
REDHAT-BUG-2493325 affects OpenJS Node.js 22, 24, and 26.
5
Is there a workaround for REDHAT-BUG-2493325?
Currently, there are no documented workarounds for REDHAT-BUG-2493325; updating Node.js is recommended.