node is vulnerable to Denial of Service (DoS)
80
High Risk
Affected versions of the package are vulnerable to a denial-of-service condition due to improper HTTP/2 session memory accounting. When header blocks are handed off to JavaScript, their memory was immediately decremented from maxSessionMemory even though the corresponding objects remain alive for the lifetime of the stream. A remote attacker can send many requests with large headers on stalled streams, bypassing the session memory limit and causing unbounded memory growth.
You are affected if you are using a version that falls within the vulnerable range and your application uses the Node.js HTTP/2 server (http2).
node is vulnerable to Denial of Service (DoS) in versions 23.0.0 - 24.18.0 and 22.0.0 - 22.23.1.
Upgrade the node library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant