CVE-2026-21714Patch(nodejs / node.js)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch nodejs node.js systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up. This vulnerability affects HTTP2 users on Node.js 20, 22, 24 and 25.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-401

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • node.js

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 8 signals
  • Technical details provided in 7 signals
  • Disclosure: 3 classified signals
  • Peaked 6d ago at 2 mentions (2026-03-24); latest day: 1
  • 10 total mentions across 7 days

Affected systems

Vendors
Products
node.js

Deep dive

Activity timeline10 mentions / 7d
01122Mentions · 2026-03-24: 2Mentions · 2026-03-25: 1Mentions · 2026-03-30: 2Mentions · 2026-03-31: 2Mentions · 2026-04-09: 1Mentions · 2026-04-22: 1Mentions · 2026-05-05: 1Patch / Workaround · 2026-03-24: 2Patch / Workaround · 2026-03-25: 1Patch / Workaround · 2026-03-30: 2Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-22: 1Patch / Workaround · 2026-05-05: 1Technical Details · 2026-03-24: 2Technical Details · 2026-03-31: 2Technical Details · 2026-04-09: 1Technical Details · 2026-04-22: 1Technical Details · 2026-05-05: 103-2403-2503-3003-3104-0904-2205-05
Signal classification2 categories
Patch
770.0%
Disclosure
330.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-242
Patch2
2026-03-251
Patch1
2026-03-302
Patch2
2026-03-312
Disclosure2
2026-04-091
Patch1
2026-04-221
Patch1
2026-05-051
Disclosure1
Full discourse10 posts
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nodejs22 モジュール更新情報 22.22.2-1 KUSANAGI 9 を構成している各モジュールのアップデートを行いました。 アップデートにより適用される各モジュールのバージョンは、以下のとおりとなります。 nodejs 22.22.2-1 この更新には脆弱性(CVE-2026-21637, CVE-2026-21710, CVE-2026-21713, CVE-2026-21714, CVE-2026-21717, CVE-2026-21715, CVE-202... https://kusanagi.tokyo/releases/23908/

    Post summary

    The post announces an update to the KUSANAGI Node.js module that fixes several CVEs, effectively providing a patch.

    01020120
    200 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Fedora 43 and 44 ship Node.js 20 with multiple DoS flaws CVE-2026-21717, CVE-2026-21714, CVE-2026-1525, CVE-2026-1526, fixed in urgent 20.20.2 update. https://threatcluster.io/cluster/critical-denial-of-service-vulnerabilities-in-nodejs-20-affe-ffaf0480

    Post summary

    The text announces that Fedora 43 and 44 ship Node.js 20 containing several DoS vulnerabilities, which have now been fixed in an urgent 20.20.2 update.

    0010050
    181 followersView on X
  • Aun shah/ Ali memon@Aunshah102
    Patch

    @rafaelgss RafaelGSS also contributed fixes for CVE-2026-21714 and CVE-2026-21712, addressing NGHTTP2_ERR_FLOW_CONTROL errors and URL parsing crashes respectively. 7/17

    Post summary

    The post indicates that RafaelGSS has contributed fixes for CVE‑2026‑21714 and CVE‑2026‑21712, addressing flow control errors and URL parsing crashes, showing that patches have been released.

    1000022
    17 followersView on X
  • ThreatCluster@threatcluster
    Patch

    BREAKING: SUSE ships Node.js 22.22.2 for openSUSE Leap 15.6 and SLE 15 SP6-SP7, fixing CVE-2026-21714-21717 enabling HTTP/2 memory leaks, hash collisions and file permission abuse. https://threatcluster.io/cluster/critical-security-flaws-in-nodejs-22-affecting-opensuse-and--8d771c1b

    Post summary

    SUSE has released Node.js 22.22.2 for openSUSE Leap 15.6 and SLE 15 SP6‑SP7, addressing CVE-2026-21714 to 21717 that caused HTTP/2 memory leaks, hash collisions, and file permission abuse.

    0000081
    160 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-21714 A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed th… https://www.cve.org/CVERecord?id=CVE-2026-21714 ----- Traducción: CVE-2026-21714 Se … http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-21714, a memory‑leak vulnerability in Node.js HTTP/2, and provides a link to the official CVE record.

    0000028
    65 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-21714 A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed th… https://www.cve.org/CVERecord?id=CVE-2026-21714

    Post summary

    This entry announces the disclosure of CVE‑2026‑21714, a Node.js HTTP/2 memory‑leak flaw triggered by WINDOW_UPDATE frames that inflate the flow control window beyond limits.

    00000218
    56.9K followersView on X
  • 草薙 沙耶(KUSANAGI)@kusanagi_saya
    Patch

    kusanagi-nodejs22 Module Update 22.22.2-1 KUSANAGI 9 modules have been updated. The updated modules are as follows: nodejs 22.22.2-1 This update includes support for vulnerability(CVE-2026-21637, CVE-2026-21710, CVE-2026-21713, CVE-2026-21714,... https://kusanagi.tokyo/en/releases/23909/

    Post summary

    KUSANAGI released module update 22.22.2‑1 to patch multiple CVEs, but no PoC, exploit, or detailed vulnerability information is provided.

    0000065
    200 followersView on X
  • ティー🌐@TeeTheta
    Patch

    対処された脆弱性(22.x対象8件) CVE-2026-21637 (High) CVE-2026-21710 (High) CVE-2026-21713 (Medium) CVE-2026-21714 (Medium) CVE-2026-21717 (Medium) CVE-2026-21715 (Low) CVE-2026-21716 (Low) undici 6.24.1/7.24.4 への依存更新

    Post summary

    Eight CVEs affecting version 22.x were resolved, and the vulnerability is mitigated by updating the undici dependency to versions 6.24.1/7.24.4.

    0000071
    1 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v24.14.1 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリースです。 • undiciを7.24.4に更新 • npmを11.11.0にアップグレード • V8の依存関係を更新 🔧 重要な修正: • (CVE-2026-21710) headersDistinct/trailersDistinctにnullプロトタイプを使用 • (CVE-2026-21637) SNICallback呼び出しをtry/catchでラップ • (CVE-2026-21717) 配列インデックスのハッシュ衝突をテスト • (CVE-2026-21713) Web Cryptography HMACおよびKMACでタイミング安全な比較を使用 • (CVE-2026-21714) NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 • (CVE-2026-21712) 異なるURL形式でのURLクラッシュを処理 • (CVE-2026-21716) lib/fs/promisesにパーミッションチェックを含める • (CVE-2026-21715) realpath.nativeにパーミッションチェックを追加 #GitHub #Release #Node.js

    Post summary

    Node.js v24.14.1 was released as a security patch fixing several CVEs, with technical details of the fixes provided.

    0000066
    2 followersView on X
  • ダース葱@darthnegi
    Patch

    🚀 Node.js v25.8.2 がリリースされました。 📅 リリース日: 2026-03-24 📦 種別: patch ✨ 主な変更点: • セキュリティリリース。 🔧 重要な修正: • SNICallbackの呼び出しをtry/catchでラップ (CVE-2026-21637) - 高 • headersDistinct/trailersDistinctにnullプロトタイプを使用 (CVE-2026-21710) - 高 • pipe_wrap.ccにパーミッションチェックを追加 (CVE-2026-21711) - 中 • 異なるURL形式でのURLクラッシュを処理 (CVE-2026-21712) - 中 • Web Cryptography HMACおよびKMACでタイミングセーフな比較を使用 (CVE-2026-21713) - 中 • NGHTTP2_ERR_FLOW_CONTROLエラーコードを処理 (CVE-2026-21714) - 中 • 配列インデックスハッシュ衝突のテスト (CVE-2026-21717) - 中 • realpath.nativeにパーミッションチェックを追加 (CVE-2026-21715) - 低 • lib/fs/promisesにパーミッションチェックを追加 (CVE-2026-21716) - 低 #GitHub #Release #Node.js

    Post summary

    Node.js v25.8.2 was released as a patch, addressing multiple CVEs (CVE‑2026‑21637 to 21718) with varying severity, but no PoC, exploit, or active exploitation is reported.

    0000049
    2 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appnodejsnode.js---

Explore more