A malformed `HTTP/2 HEADERS` frame with oversized,...
High severity
Unreviewed
Published
Jan 20, 2026
to the GitHub Advisory Database
•
Updated Jan 21, 2026
Description
Published by the National Vulnerability Database
Jan 20, 2026
Published to the GitHub Advisory Database
Jan 20, 2026
Last updated
Jan 21, 2026
A malformed
HTTP/2 HEADERSframe with oversized, invalidHPACKdata can cause Node.js to crash by triggering an unhandledTLSSocketerrorECONNRESET. Instead of safely closing the connection, the process crashes, enabling a remote denial of service. This primarily affects applications that do not attach explicit error handlers to secure sockets, for example:References