LiveActive security incident?Get immediate response
CVE Record

CVE-2026-47219: find-my-way is Vulnerable to DDoS with HTTP2

find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9.7.0 are vulnerable to remotely triggerable DoS in find-my-way when it is used with Node's HTTP/2 server. The lookup() function passes req.method into find(), and find() indexes this.trees[method]. Since this.trees is a normal object, HTTP/2 method values like constructor, toString, or __proto__ can resolve inherited object properties instead of returning undefined. The code then treats that value like a router node and crashes when it reaches currentNode.prefix.length. This issue has been fixed in version 9.0.7.

HighCVSS 7.5Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

A remote, unauthenticated client can crash affected applications using find-my-way with Node.js HTTP/2. Repeated crashes could disrupt service availability. The sources contain conflicting affected and fixed version numbers, so teams should confirm the correct patched release before upgrading.

Executive priority

Treat as a high-priority availability risk for public HTTP/2 services. Identify exposed deployments promptly and schedule an expedited, vendor-verified update. The version discrepancy prevents confidently naming one target release from this bundle alone.

Technical view

lookup() forwards an HTTP/2 method value into find(), which indexes a normal JavaScript object. Method names matching inherited properties can return non-router values. Subsequent router-node processing dereferences prefix.length and crashes the process, causing denial of service without authentication or user interaction.

Likely exposure

Exposure is limited to applications using affected find-my-way versions with Node.js HTTP/2. Internet-facing services are the primary concern. Applications not using HTTP/2, or not using this router, are not established as affected by the supplied evidence.

Exploitation context

The CVSS score is 7.5 because exploitation is network-accessible, low-complexity, unauthenticated, and availability-focused. The CVE is not listed as KEV, and the supplied sources provide no evidence of active exploitation.

Researcher notes

The root issue combines insufficient method validation with prototype-inherited object properties and an uncaught type assumption. The bundle says versions below 9.7.0 are affected but separately says 9.0.7 fixes the issue; this inconsistency materially reduces remediation certainty.

Mitigation direction

  • Inventory applications using find-my-way and determine whether Node.js HTTP/2 is enabled.
  • Consult the vendor advisory to resolve the conflicting affected and fixed version numbers.
  • Upgrade to the vendor-confirmed patched release after compatibility testing.
  • Prioritize internet-facing HTTP/2 services and maintain normal availability monitoring during remediation.

Validation and detection

  • Confirm the deployed find-my-way version from dependency manifests and resolved dependency data.
  • Verify whether each affected application creates or receives traffic through Node.js HTTP/2 servers.
  • Confirm the installed version is vendor-designated as non-vulnerable.
  • Use approved, non-production testing to verify malformed method handling does not terminate the application.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-20: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cwe · low confidence lookup

CWE-248: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2026-47219 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.5 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
3Timeline events
1ADP providers
2Source links

SSVC decision data

CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: noneAutomatable: yesTechnical Impact: partial

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.5CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H3.93.6GitHub_M

Vulnerability scoring details

Base CVSS 3.1 score

7.5High
CVSS 3.1 vector shape for CVE-2026-47219Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Vulnerability timeline

Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.

  1. CVE reservedCVE Program

    The CVE ID was reserved by the assigning CNA.

  2. CVE publishedCVE Program

    The CVE record was published.

  3. CVE updatedCVE Program

    The CVE record metadata indicates this as the latest update time.

ADP provider summaries

CISA-ADPCISA ADP Vulnrichment
other:ssvc

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
delvedorfind-my-way< 9.7.0Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.