CVE-2026-56848 | Node.js up to 22.23.1/24.18.0/26.5.0 HTTP/2 nghttp2_session_mem_send use after free
A vulnerability was found in Node.js up to 22.23.1/24.18.0/26.5.0. It has been declared as critical. Impacted is the function nghttp2_session_mem_send of the component HTTP2. Such manipulation leads to use after free.
This vulnerability is traded as CVE-2026-56848. The attack may be launched remotely. There is no exploit available.VulDB Recent EntriesRead More