CVE-2024-27983: high-severity vulnerability in NodeJS Node
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
An attacker can crash a Node.js HTTP/2 server by sending specially crafted HTTP/2 frames followed by abruptly closing the connection, leaving unprocessed data in memory that causes the server to become unavailable.
A race condition exists in Node.js HTTP/2 implementation where sending CONTINUATION frames and abruptly terminating the TCP connection triggers premature Http2Session destruction while headers are still being processed in nghttp2 memory, leading to denial of service without requiring authentication or special privileges.
In the same product, most dangerous first.