High severity7.5NVD Advisory· Published Jun 18, 2026· Updated Aug 18, 2026
CVE-2026-48937
CVE-2026-48937
Description
A flaw in Node.js HTTP/2 server API can cause servers to keep accepting data even after sending a GOAWAY frame. This vulnerability affects two supported release lines: Node.js 22 and Node.js 24.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- osv-coords5 versionspkg:bitnami/nodepkg:bitnami/node-minpkg:rpm/opensuse/nodejs22&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/nodejs24&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/nodejs24&distro=openSUSE%20Tumbleweed
< 22.23.0+ 4 more
- (no CPE)range: < 22.23.0
- (no CPE)range: < 22.23.0
- (no CPE)range: < 22.23.0-160000.1.1
- (no CPE)range: < 24.18.0-160000.1.1
- (no CPE)range: < 24.17.0-1.1
Patches
Vulnerability mechanics
References
2- nodejs.org/en/blog/vulnerability/june-2026-security-releasesnvdPatchVendor Advisory
- hackerone.com/reports/3658225nvdIssue TrackingThird Party Advisory
News mentions
1- Node.js Fixes 12 Vulnerabilities, Including 2 High-Severity Authentication BypassesCyber Security News · Jun 19, 2026