CVE-2026-47219: CWE-20: Improper Input Validation in delvedor find-my-way
find-my-way versions prior to 9.0.7 contain an improper input validation vulnerability that allows a remote denial of service (DoS) when used with Node's HTTP/2 server. The issue arises because HTTP/2 method values like constructor, toString, or __proto__ can access inherited object properties in the router's internal trees object, causing the application to crash.
AI Analysis
Technical Summary
The find-my-way HTTP router framework versions before 9.0.7 are vulnerable to a remotely triggerable denial of service due to improper input validation. Specifically, the lookup() function passes the HTTP request method to the find() function, which indexes an internal object this.trees by method name. Since this.trees is a normal JavaScript object, HTTP/2 method names such as constructor, toString, or __proto__ can resolve to inherited properties rather than undefined. This leads to the code treating these inherited properties as router nodes, causing a crash when accessing currentNode.prefix.length. This vulnerability has been fixed in version 9.0.7.
Potential Impact
An attacker can remotely cause a denial of service by sending specially crafted HTTP/2 requests with method names that exploit the improper input validation, crashing the application using find-my-way versions prior to 9.0.7. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Upgrade find-my-way to version 9.0.7 or later, where this issue has been fixed. No other mitigation or workaround is indicated.
CVE-2026-47219: CWE-20: Improper Input Validation in delvedor find-my-way
Description
find-my-way versions prior to 9.0.7 contain an improper input validation vulnerability that allows a remote denial of service (DoS) when used with Node's HTTP/2 server. The issue arises because HTTP/2 method values like constructor, toString, or __proto__ can access inherited object properties in the router's internal trees object, causing the application to crash.
CVSS v3.1
Score 7.5high
Affected software
delvedor
find-my-way
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The find-my-way HTTP router framework versions before 9.0.7 are vulnerable to a remotely triggerable denial of service due to improper input validation. Specifically, the lookup() function passes the HTTP request method to the find() function, which indexes an internal object this.trees by method name. Since this.trees is a normal JavaScript object, HTTP/2 method names such as constructor, toString, or __proto__ can resolve to inherited properties rather than undefined. This leads to the code treating these inherited properties as router nodes, causing a crash when accessing currentNode.prefix.length. This vulnerability has been fixed in version 9.0.7.
Potential Impact
An attacker can remotely cause a denial of service by sending specially crafted HTTP/2 requests with method names that exploit the improper input validation, crashing the application using find-my-way versions prior to 9.0.7. There is no impact on confidentiality or integrity reported.
Mitigation Recommendations
Upgrade find-my-way to version 9.0.7 or later, where this issue has been fixed. No other mitigation or workaround is indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-18T22:25:21.258Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a692bbe9c2644c7f84c146c
Added to database: 07/28/2026, 22:22:54 UTC
Last enriched: 08/05/2026, 14:54:33 UTC
Last updated: 09/11/2026, 07:31:53 UTC
Views: 65
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.