CVE-2026-47219: find-my-way is Vulnerable to DDoS with HTTP2
find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9.7.0 are vulnerable to remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server. The lookup() function passes req.method into find(), and find() indexes this.trees[method]. Since this.trees is a normal object, HTTP/2 method values like constructor, toString, or __proto__ can resolve inherited object properties instead of returning undefined. The code then treats that value like a router node and crashes when it reaches currentNode.prefix.length. This issue has been fixed in version 9.0.7.
Security readout for executives and security teams
Plain-English summary
A remote, unauthenticated client can crash affected applications using find-my-way with Node.js HTTP/2. Repeated crashes could disrupt service availability. The sources contain conflicting affected and fixed version numbers, so teams should confirm the correct patched release before upgrading.
Executive priority
Treat as a high-priority availability risk for public HTTP/2 services. Identify exposed deployments promptly and schedule an expedited, vendor-verified update. The version discrepancy prevents confidently naming one target release from this bundle alone.
Technical view
lookup() forwards an HTTP/2 method value into find(), which indexes a normal JavaScript object. Method names matching inherited properties can return non-router values. Subsequent router-node processing dereferences prefix.length and crashes the process, causing denial of service without authentication or user interaction.
Likely exposure
Exposure is limited to applications using affected find-my-way versions with Node.js HTTP/2. Internet-facing services are the primary concern. Applications not using HTTP/2, or not using this router, are not established as affected by the supplied evidence.
Exploitation context
The CVSS score is 7.5 because exploitation is network-accessible, low-complexity, unauthenticated, and availability-focused. The CVE is not listed as KEV, and the supplied sources provide no evidence of active exploitation.
Researcher notes
The root issue combines insufficient method validation with prototype-inherited object properties and an uncaught type assumption. The bundle says versions below 9.7.0 are affected but separately says 9.0.7 fixes the issue; this inconsistency materially reduces remediation certainty.
Mitigation direction
Inventory applications using find-my-way and determine whether Node.js HTTP/2 is enabled.
Consult the vendor advisory to resolve the conflicting affected and fixed version numbers.
Upgrade to the vendor-confirmed patched release after compatibility testing.
Prioritize internet-facing HTTP/2 services and maintain normal availability monitoring during remediation.
Validation and detection
Confirm the deployed find-my-way version from dependency manifests and resolved dependency data.
Verify whether each affected application creates or receives traffic through Node.js HTTP/2 servers.
Confirm the installed version is vendor-designated as non-vulnerable.
Use approved, non-production testing to verify malformed method handling does not terminate the application.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
cwe · low confidence lookup
CWE-20: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.