CVE-2023-35945

Uncontrolled Resource Consumption
Affects
Node.js
in
Node.js
No items found.
Versions
>=8.4.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <=16.20.2 >=17.0.0 <=17.9.1 >=18.0.0 <18.18.2 >=19.0.0 <=19.9.0 >=20.0.0 <20.5.0

Patch Available.

Exclamation circle icon
Patch Available

This Vulnerability has been fixed in the Never-Ending Support (NES) version offered by HeroDevs.

Overview

Node.js is a JavaScript runtime built on Chrome's V8 JavaScript engine. It uses an event-driven, non-blocking I/O model and is widely used for web applications and server-side development. Node.js implements its http2 module on top of nghttp2, a C library for the HTTP/2 protocol that Node.js bundles at deps/nghttp2 and compiles into the runtime. A flaw in the bundled nghttp2 therefore reaches Node.js directly.

A vulnerability (CVE-2023-35945) has been identified in the nghttp2 library bundled with Node.js. When nghttp2 cannot send a HEADERS or PUSH_PROMISE frame, for example because the peer has sent a GOAWAY frame and the connection may no longer open streams, it takes an error path that returns before freeing the pending request's bookkeeping structure and compressed headers. Each time this happens the memory is leaked, and repeated leaks can exhaust memory and cause a denial of service.

This flaw maps to CWE-400 (Uncontrolled Resource Consumption), where software does not properly control the allocation of a limited resource; NVD also lists CWE-459 (Incomplete Cleanup). In nghttp2, the clean-up code for a request that could not be sent sat after a return statement on one error branch, so it never ran on that branch.

The CVE was assigned by the Envoy proxy project, which hit the leak in its HTTP/2 client when a malicious upstream server sent RST_STREAM followed immediately by GOAWAY. The nghttp2 maintainer has noted that the leak also requires the application's stream-close callback to report a fatal error, or nghttp2 to run out of memory, at that moment. Node.js's http2 stream-close callback always reports success, so in Node.js the leak is only expected under memory pressure, which makes practical exploitation through the http2 module unlikely. This issue affects every Node.js release line that bundles nghttp2, from 8.4.0 through 20.x, up to the versions listed above.

Details

Module Info

  • Product: Node.js
  • Affected packages: node (bundles nghttp2 under deps/nghttp2)
  • Affected versions: >=8.4.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <=16.20.2 >=17.0.0 <=17.9.1 >=18.0.0 <18.18.2 >=19.0.0 <=19.9.0 >=20.0.0 <20.5.0
  • GitHub repository: https://github.com/nodejs/node
  • Published packages: https://nodejs.org/en/download
  • Package manager: Not applicable; Node.js is distributed as runtime builds from nodejs.org rather than as a published npm package
  • Fixed in: Node.js 20.5.0 (July 18, 2023), which updated the bundled nghttp2 to 1.55.1, and 18.18.2 (October 13, 2023), which updated it to 1.57.0; Node.js NES v16.20.3 (16.x line, shipped July 30, 2024), v14.21.4 (14.x line, shipped August 24, 2024) and v12.22.13 (12.x line, shipped November 10, 2025), none of which received an upstream fix. The other release lines listed above never received an updated nghttp2

Vulnerability Info

This High-severity vulnerability is found in nghttp2 before 1.55.1, the HTTP/2 library that Node.js bundles and statically links at deps/nghttp2. NVD assigns a CVSS v3.1 score of 7.5, matching the score in Envoy's advisory.

When nghttp2 prepares an outgoing frame that would open a stream and the preparation fails, it closes the stream that was being opened and frees the frame's resources. In the vulnerable versions, if closing that stream itself returned a fatal error, the code returned straight away, skipping the lines that free the pending request's bookkeeping structure and header block. The fix rearranges that branch so the resources are always released before a fatal error is returned. See the nghttp2 fix commit for the exact change.

In Envoy, an upstream HTTP/2 server could trigger a leak per request by resetting the stream and then sending GOAWAY with a last-stream ID of 0, and a steady flow of client requests turned that into memory exhaustion. In Node.js, the equivalent path is an http2 client talking to a malicious server, but because Node.js's stream-close callback never returns a fatal error, the leak needs nghttp2 to also hit an out-of-memory error at that point.

Note: Node.js applications that do not use the http2 module are not exposed by this issue, since the http and https modules do not use nghttp2.

Mitigation

Users of the affected components should apply one of the following mitigations:

  • Upgrade to a currently supported Node.js LTS release (22.x or 24.x), both of which bundle an nghttp2 version that includes this fix.
  • Migrate affected applications away from the End-of-Life Node.js release lines.
  • Leverage a commercial support partner like HeroDevs for post-EOL security support, through Node.js NES.

Credits

  • Reported through the Envoy proxy project (GHSA-jfxv-29pc-x22r)
  • Tatsuhiro Tsujikawa from the nghttp2 project (remediation developer)
Vulnerability Details
Severity
Level
CVSS Assessment
Low
>=0 <4
Medium
>=4 <6
High
>=6 <8
Critical
>=8 <10
High
ID
CVE-2023-35945
PROJECT Affected
Node.js
Versions Affected
>=8.4.0 <=8.17.0 >=9.0.0 <=9.11.2 >=10.0.0 <=10.24.1 >=11.0.0 <=11.15.0 >=12.0.0 <=12.22.12 >=13.0.0 <=13.14.0 >=14.0.0 <=14.21.3 >=15.0.0 <=15.14.0 >=16.0.0 <=16.20.2 >=17.0.0 <=17.9.1 >=18.0.0 <18.18.2 >=19.0.0 <=19.9.0 >=20.0.0 <20.5.0
NES Versions Affected
Published date
October 8, 2026
≈ Fix date
July 30, 2024
Category
Uncontrolled Resource Consumption
Vex Document
Download VEXHow do I use it?
Sign up for the latest vulnerability alerts fixed in
NES for Node.js
Rss feed icon
Subscribe via RSS
or

By submitting the form I acknowledge receipt of our Privacy Policy.

Thanks for signing up for our Newsletter! We look forward to connecting with you.
Oops! Something went wrong while submitting the form.