CVE-2026-21714
Advisory lineage Upstream: 0 Downstream: 19
Awaiting Analysis
Published: 30 Mar 2026, 19:07
Last modified:31 Mar 2026, 18:05
Vulnerability Summary
Overall Risk (default)
low
21/100 CVSS Score
5.3 MEDIUM
v3.0 (cve.org)
EPSS Score
0.45% LOW
0% probability 0.00%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
30 Mar 2026, 19:07
Published
Vulnerability first disclosed
31 Mar 2026, 18:05
Last Modified
Vulnerability information updated
Description
A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.
CVSS Metrics
- v3.0•MEDIUM•Score: 5.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS Trends
Current EPSS score: 0.45%• Percentile: 36%
Techniques & Countermeasures
- CWE-401•Missing Release of Memory after Effective Lifetime
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Affected Systems
- nodejs•node
20.20.1 | 22.22.1 | 24.14.0 | 25.8.1