THREAT OPS › Threat News › [NVD] CVE-2026-21714 (MEDIUM 5.3) — A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned
[NVD] CVE-2026-21714 (MEDIUM 5.3) — A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned
CVE-2026-21714 CVSS: 5.3 MEDIUM Published: 2026-03-30T20:16:19.573
A memory leak occurs in Node.js HTTP/2 servers when a client sends WINDOW_UPDATE frames on stream 0 (connection-level) that cause the flow control window to exceed the maximum value of 2³¹-1. The server correctly sends a GOAWAY frame, but the Http2Session object is never cleaned up.
This vulnerability affects HTTP2 users on Nod
Indicators of compromise
- CVE-2026-21714cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-21714