August 30, 2026
- Node.js disclosed six HackerOne reports covering 22.x, 24.x and 26.x: a high-severity HTTP/2 heap use-after-free via re-entrant
nghttp2_session_mem_send()(CVE-2026-56848), HTTP/2 memory exhaustion through retained header blocks bypassingmaxSessionMemory(CVE-2026-56846), request desync/smuggling when headers such asContent-Lengthare silently dropped past the header limit (CVE-2026-58044), adns.resolveAny()crash on 256+ A records (CVE-2026-58042), anode:zlibreachable assertion via spoofed TypedArraybyteLength(CVE-2026-58045), and stalenode:sqliteiterators re-executing cached prepared statements (CVE-2026-58041) (HTTP/2 UAF report, smuggling report). · Vulnerabilities & Exploitation
in CISA Adds a Kernel Bug That OpenAI's Own Agents Exploited