daily cyber × ai intelligence

index

tagged

[CVE-2026-56846]

1 edition · 1 item

August 30, 2026

  • Node.js disclosed six HackerOne reports covering 22.x, 24.x and 26.x: a high-severity HTTP/2 heap use-after-free via re-entrant nghttp2_session_mem_send() (CVE-2026-56848), HTTP/2 memory exhaustion through retained header blocks bypassing maxSessionMemory (CVE-2026-56846), request desync/smuggling when headers such as Content-Length are silently dropped past the header limit (CVE-2026-58044), a dns.resolveAny() crash on 256+ A records (CVE-2026-58042), a node:zlib reachable assertion via spoofed TypedArray byteLength (CVE-2026-58045), and stale node:sqlite iterators re-executing cached prepared statements (CVE-2026-58041) (HTTP/2 UAF report, smuggling report). · Vulnerabilities & Exploitation

in CISA Adds a Kernel Bug That OpenAI's Own Agents Exploited