node is vulnerable to Use-After-Free
80
High Risk
Affected versions of Node.js are vulnerable to a heap-use-after-free due to improper handling of re-entrant HTTP/2 operations. A flaw in the interaction between nghttp2_session_mem_recv() and nghttp2_session_mem_send() allows memory to be accessed after it has been freed when processing specially crafted HTTP/2 frames. An attacker could exploit this vulnerability to cause a denial of service by crashing the application or, in certain circumstances, achieve arbitrary code execution.
You are affected if you are using a version that falls within the vulnerable range.
node is vulnerable to Use-After-Free in versions 25.0.0 - 26.5.0, 23.0.0 - 24.18.0 and 0.0.1 - 22.23.1.
Upgrade the node library to a patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant