CVE-2026-47219 with a CVSS score of 7.5 is a remotely triggerable denial-of-service vulnerability affecting find-my-way versions <= 9.6.0 in the find-my-way package when used with Node's HTTP/2 server, allowing an attacker to crash the application by passing a malicious HTTP method into the lookup function, which then indexes the httpTrees object using the method value. This can resolve inherited object properties instead of returning undefined, leading to a crash when reaching the currentNode prefix length. The vulnerability affects versions prior to 9.7.0 and can be exploited via the environment template management API by an unauthenticated attacker with normal user privileges, resulting in high business impact for organizations relying on find-my-way for routing and navigation purposes.
We recommend you to update find-my-way to version 9.7.0.[/subscribe_to_unlock_form]
CVE-2026-47219 with a CVSS score of 7.5 is a remotely triggerable denial-of-service vulnerability affecting find-my-way versions <= 9.6.0 in the find-my-way package when used with Node's HTTP/2 server, allowing an attacker to crash the application by passing a malicious HTTP method into the lookup function, which then indexes the httpTrees object using the method value. This can resolve inherited object properties instead of returning undefined, leading to a crash when reaching the currentNode prefix length. The vulnerability affects versions prior to 9.7.0 and can be exploited via the environment template management API by an unauthenticated attacker with normal user privileges, resulting in high business impact for organizations relying on find-my-way for routing and navigation purposes.
We recommend you to update find-my-way to version 9.7.0.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]