CVE-2026-48937: Node.js

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a `GOAWAY` frame. This vulnerability affects two supported release lines: **Node.js 22** and **Node.js 24**.

Affected products

  • Node.js Node.js: from 22.0, before 22.23.0 (fixed in 22.23.0); from 24.0.0, before 24.17.0 (fixed in 24.17.0)

Published 2026-06-18. Last modified 2026-08-18.